← Back to browse · API

CVE-2022-40089

Severity
CRITICAL
CVSS
9.8
EPSS
0.02059
Risk score
39.92
CISA KEV
No
PoC
No
Published
2022-09-22
Modified
2025-05-27
First seen
2026-08-07
Aliases
EUVD-2022-43408, GHSA-7448-X2VG-9PM2
Products
n/a:n/a n/a
Sources
euvd EUVD-2022-43408

Description

A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploitable when the directive allow_url_include is set to On.

References