← Vulnerability feed

Vulnerability record · CVE-2022-37190 · published 13 September 2022

CVE-2022-37190: CuppaCMS authenticated remote code execution via api parameters

Cuppacms · Cuppacms

CuppaCMS 1.0 lets an authenticated user control the action and function parameters of /api/index.php, which leads to remote code execution. Because the flaw is in a core API endpoint, any account able to reach it can turn normal access into code execution on the server.

8.8 CVSS 3.1 High EPSS 46% · top 1.2%
8.8CVSS 3.1 base score
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from "/api/index.php.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityCVSS 8.8 with low attack complexity and high EPSS, but exploitation requires valid credentials, keeping it below critical.

What it is

CuppaCMS 1.0 lets an authenticated user control the action and function parameters of /api/index.php, which leads to remote code execution. Because the flaw is in a core API endpoint, any account able to reach it can turn normal access into code execution on the server.

Impact

An attacker with valid credentials gains remote code execution on the host, allowing full compromise of confidentiality, integrity and availability of the application and its data.

Attack surface

Reached over the network through /api/index.php with attacker-controlled action and function parameters. Authentication is required (PR:L) and no user interaction is needed (UI:N).

Exploitation

Not listed in CISA KEV, but public exploit references exist and EPSS is high at roughly 0.46 (98.7th percentile), indicating elevated likelihood of exploitation.

What to do

  • Apply the vendor fix or upgrade CuppaCMS past 1.0 if an update is available; no fixed version is stated in this record.
  • Restrict access to /api/index.php to trusted networks or administrative users only.
  • Enforce least privilege and strong unique credentials for all CuppaCMS accounts, and audit for unused or default accounts.
  • Add input validation or a WAF rule blocking unexpected action and function values on the API endpoint.

Detection

  • Monitor web logs for POST or GET requests to /api/index.php with unusual action or function parameter values.
  • Alert on child processes spawned by the web server user (php-fpm, apache, nginx) indicating command execution.
  • Review authentication logs for successful logins followed immediately by API calls from the same source.
  • Watch for outbound connections or file writes from the web server process that deviate from normal behavior.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/CuppaCMS/CuppaCMS/issues/22 ExploitIssue TrackingThird Party Advisory
https://github.com/badru8612/Authenticated-RCE-CuppaCMS ExploitIssue TrackingThird Party Advisory
https://github.com/CuppaCMS/CuppaCMS/issues/22 ExploitIssue TrackingThird Party Advisory
https://github.com/badru8612/Authenticated-RCE-CuppaCMS ExploitIssue TrackingThird Party Advisory

Track CVE-2022-37190 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-47990Cuppacms sql injection vulnerabilitySQL Injection vulnerability in components/table_manager/html/edit_admin_table.php in CuppaCMS V1.0 allows attackers to run arbitrary SQL commands via…EPSS 0.78%9.8CVE-2023-39681Cuppacms code injection vulnerabilityCuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at /Configuration.php. This vul…EPSS 1.7%9.8CVE-2022-38296Cuppacms unrestricted file upload vulnerabilityCuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.EPSS 5.1%9.8CVE-2022-27984Cuppacms sql injection vulnerabilityCuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/…EPSS 6.8%9.8CVE-2022-27985Cuppacms sql injection vulnerabilityCuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.EPSS 6.6%9.8CVE-2022-25495Cuppacms unrestricted file upload vulnerabilityThe component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a c…EPSS 2.2%9.8CVE-2022-25498Cuppacms code injection vulnerabilityCuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php.EPSS 3.1%9.8CVE-2018-19559Cuppacms sql injection vulnerabilityCuppaCMS before 2018-11-12 has SQL Injection in administrator/classes/ajax/functions.php via the reference_id parameter.EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2022-37190), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.