Embedded malicious code (backdoor) in School Management Pro - CVE-2022-1609
Published: May 23, 2022 / Updated: July 5, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to the application.
The vulnerability exists due to presence of embedded malicious functionality in the application code (aka backdoor) that allows a remote attacker to gain unauthorized access to the application.
Note, the vulnerability is being actively exploited in the wild.
Affected software
How to mitigate CVE-2022-1609
Links to Public Exploits and PoC-codes
- Exploit #9173 - cve-2022-1609-exploit (Exploit for CVE-2022-1609 WordPress Weblizar Backdoor.) (July 5, 2023)
- Exploit #9001 - cve-2022-1609-exploit (Exploit for CVE-2022-1609 WordPress Weblizar Backdoor.) (April 22, 2023)
- Exploit #8008 - -CVE-2022-1609 (Bash poc for CVE-2022-1609 WordPress Weblizar Backdoor) (June 9, 2022)
- Exploit #8001 - CVE-2022-1609 () (June 9, 2022)
- Exploit #7955 - CVE-2022-1609 (Bash poc for CVE-2022-1609 WordPress Weblizar Backdoor) (June 3, 2022)
- Exploit #7904 - CVE-2022-1609 (CVE-2022-1609 WordPress Weblizar后门) (May 27, 2022)