diff --git a/2022/4xxx/CVE-2022-4136.json b/2022/4xxx/CVE-2022-4136.json index bb0dbf1d0fd..d23e545dd1a 100644 --- a/2022/4xxx/CVE-2022-4136.json +++ b/2022/4xxx/CVE-2022-4136.json @@ -36,7 +36,7 @@ "description_data": [ { "lang": "eng", - "value": "Attackers can call any existing functions at will, control the target server to access, download, create files, delete files, etc. Access may make the server a dos server. Download, so that an attacker can download the PHP Trojan to the server. Creating and deleting will destroy normal services. More than ten IPs are using this service." + "value": "Dangerous method exposed which can lead to RCE in qmpass/leadshop v1.4.15 allows an attacker to control the target host by calling any function in leadshop.php via the GET method." } ] }, @@ -86,4 +86,4 @@ "advisory": "fe418ae1-7c80-4d91-8a5a-923d60ba78c3", "discovery": "EXTERNAL" } -} \ No newline at end of file +}