{"id":"CVE-2022-42092","details":"Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third parties dispute this and argue that advanced permissions are required.","aliases":["GHSA-33c9-rppf-m7fq"],"modified":"2026-08-12T03:51:11.409853607Z","published":"2022-10-07T00:00:00Z","database_specific":{"isDisputed":true,"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/42xxx/CVE-2022-42092.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://grimthereaperteam.medium.com/backdrop-cms-1-22-0-unrestricted-file-upload-themes-ad42a599561c"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/42xxx/CVE-2022-42092.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-42092"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/backdrop/backdrop","events":[{"introduced":"e6aae124678820b45cce2a8cda7b9021491e2418"},{"last_affected":"e6aae124678820b45cce2a8cda7b9021491e2418"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:backdropcms:backdrop_cms:1.22.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.22.0"},{"last_affected":"1.22.0"}]}}],"versions":["1.22.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-42092.json"}}],"schema_version":"1.9.0"}