QID 731245

Date Published: 2024-03-19

QID 731245: SolarView Compact Remote Code Execution (RCE) Vulnerability

CVE-2022-29303: SolarView Compact version 6.00 is vulnerable to command injection vulnerability via conf_mail.php.

Affected Versions:
SolarView Compact version 6.00

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable installation of SolarView by sending a crafted payload to the 'conf_mail.php' endpoint as an HTTP POST request. The payload tries to execute commands such as 'cat /etc/passwd' , 'id' etc to check for code execution.

Successful exploitation of this vulnerability may allow an unauthenticated remote attacker to execute arbitrary code on the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to upgrade to the latest version of the SolarView Compact. Please refer to the Vendor Contec for more information about the latest version of SolarView Compact.

    Vendor References

    CVEs related to QID 731245

    Software Advisories
    Advisory ID Software Component Link
    Contec HomePage URL Logo www.contec.com/