An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists due to a logic issue when determining if the setup phases of the product can be run again. Once an attacker is authenticated as the new admin user they have added, it is possible to upload an executable file and achieve command execution. This is fixed in 9.5.9, 9.6.16, 9.7.8, 9.8.11, 9.9.8, 9.10.18, 9.12.8, and 9.13.0 (and later).
References
Configurations
No configuration.
History
23 Jan 2026, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-287 CWE-288 |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
23 Jan 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-23 17:16
Updated : 2026-01-26 15:03
NVD link : CVE-2022-25369
Mitre link : CVE-2022-25369
CVE.ORG link : CVE-2022-25369
JSON object : View
Products Affected
No product.
