Vulnerability record · CVE-2022-37190 · published 13 September 2022
CVE-2022-37190: CuppaCMS authenticated remote code execution via api parameters
Cuppacms · Cuppacms
CuppaCMS 1.0 lets an authenticated user control the action and function parameters of /api/index.php, which leads to remote code execution. Because the flaw is in a core API endpoint, any account able to reach it can turn normal access into code execution on the server.
Description
CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from "/api/index.php.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with low attack complexity and high EPSS, but exploitation requires valid credentials, keeping it below critical.
What it is
CuppaCMS 1.0 lets an authenticated user control the action and function parameters of /api/index.php, which leads to remote code execution. Because the flaw is in a core API endpoint, any account able to reach it can turn normal access into code execution on the server.
Impact
An attacker with valid credentials gains remote code execution on the host, allowing full compromise of confidentiality, integrity and availability of the application and its data.
Attack surface
Reached over the network through /api/index.php with attacker-controlled action and function parameters. Authentication is required (PR:L) and no user interaction is needed (UI:N).
Exploitation
Not listed in CISA KEV, but public exploit references exist and EPSS is high at roughly 0.46 (98.7th percentile), indicating elevated likelihood of exploitation.
What to do
- Apply the vendor fix or upgrade CuppaCMS past 1.0 if an update is available; no fixed version is stated in this record.
- Restrict access to /api/index.php to trusted networks or administrative users only.
- Enforce least privilege and strong unique credentials for all CuppaCMS accounts, and audit for unused or default accounts.
- Add input validation or a WAF rule blocking unexpected action and function values on the API endpoint.
Detection
- Monitor web logs for POST or GET requests to /api/index.php with unusual action or function parameter values.
- Alert on child processes spawned by the web server user (php-fpm, apache, nginx) indicating command execution.
- Review authentication logs for successful logins followed immediately by API calls from the same source.
- Watch for outbound connections or file writes from the web server process that deviate from normal behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/CuppaCMS/CuppaCMS/issues/22 | ExploitIssue TrackingThird Party Advisory |
| https://github.com/badru8612/Authenticated-RCE-CuppaCMS | ExploitIssue TrackingThird Party Advisory |
| https://github.com/CuppaCMS/CuppaCMS/issues/22 | ExploitIssue TrackingThird Party Advisory |
| https://github.com/badru8612/Authenticated-RCE-CuppaCMS | ExploitIssue TrackingThird Party Advisory |
Track CVE-2022-37190 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-37190), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.