CVE-2022-23626 EXPLOIT
8.5
HIGH · CVSS 3.1 · EPSS 9.9% (pctl 95)
Patch early
A public exploit exists.
Description
m1k1o/blog is a lightweight self-hosted facebook-styled PHP blog. Errors from functions `imagecreatefrom*` and `image*` have not been checked properly. Although PHP issued warnings and the upload function returned `false`, the original file (that could contain a malicious payload) was kept on the disk. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.
Scoring
| CVSS | 8.5 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 9.87% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2022-02-08 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| blog project | blog |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | m1k1o's Blog v.10 - Remote Code Execution (RCE) (Authenticated) | 2022-05-23 |
References
- http://packetstormsecurity.com/files/167235/m1k1os-Blog-1.3-Remote-Code-Execution.html
- https://github.com/m1k1o/blog/commit/6f5e59f1401c4a3cf2e518aa85b231ea14e8a2ef
- https://github.com/m1k1o/blog/security/advisories/GHSA-wmqj-5v54-24x4
- http://packetstormsecurity.com/files/167235/m1k1os-Blog-1.3-Remote-Code-Execution.html
- https://github.com/m1k1o/blog/commit/6f5e59f1401c4a3cf2e518aa85b231ea14e8a2ef
- https://github.com/m1k1o/blog/security/advisories/GHSA-wmqj-5v54-24x4
→ the Explorer · watch your stack · NVD