CVE-2022-1509

9.9
CRITICALCVSS v3.1 Base Score
4.53%
LOW RiskEPSS (91st percentile)

Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.

Published: 4/28/2022
Modified: 6/17/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

9.9CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVSS v2 Score

9

AV:N/AC:L/Au:S/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

4.53%LOW Exploitation Risk
91st percentile

This vulnerability has a 4.53% probability of being exploited in the next 30 days, ranking higher than 91% of all scored CVEs.

CWE Classification

Advertisement