S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-32409 Scanner

Detects 'Local File Inclusion (LFI)' vulnerability in Portal do Software Publico Brasileiro i3geo affects v. 7.0.5.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.5k
Times Used
continuous scan runs
5.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-32409
9.8
CVSS

A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to execute arbitrary PHP code via a crafted HTTP request.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Portal do Software Publico Brasileiro i3geo v7.0.5 is a free and open-source software developed by the Brazilian Government that helps to manage and display geographical information. It is used by public institutions and private companies for various purposes such as urban planning, environment management, and disaster risk reduction. The tool provides a user-friendly interface that allows users to interact with geographical data, perform analysis, and generate maps.

Recently, a critical security vulnerability was discovered in i3geo v7.0.5, registered as CVE-2022-32409. The vulnerability is related to a local file inclusion (LFI) vulnerability discovered in the codemirror.php component that can potentially allow attackers to execute arbitrary PHP code via a specially crafted HTTP request. This can potentially lead to sensitive data exposure, unauthorized access to the system, and even a complete takeover of the affected system.

When this vulnerability is exploited, attackers can use it to gain access to confidential information such as user credentials, personal identifiable information, and other sensitive data, leading to subsequent cyber attacks or espionage. In addition, malicious actors can use the vulnerability to plant backdoors in the system, performing malicious activities, or stealing sensitive information from the system.

s4e.io's pro features can immensely help to prevent similar security vulnerabilities in the future. The company offers tools and services for proactively monitoring and addressing security risks that can threaten digital assets. Through the platform's advanced analytics and vulnerability scanning, users can quickly identify potential threats, vulnerabilities, and risks and take prompt actions to mitigate them. Additionally, the platform offers user-friendly dashboards and reports that are easy to comprehend and act upon, ensuring maximum security for digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users who have installed i3geo v7.0.5 or are running web applications that use i3geo should take the necessary precautions:

  • Users should update the software to the latest version that contains a patch for the vulnerability.
  • Implementing strict input validation procedures can prevent the submission of malicious HTTP requests.
  • Making sure that security best practices are implemented such as using strong passwords, two-factor authentication, and periodically backing up data.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.