CVE-2022-47637: Apachefriends Xampp
Medium severity, CVSS 6.7. EPSS: 0.3% chance of exploitation in the next 30 days.
The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory. Common use cases execute files under C:\xampp with administrative privileges.
Affected products
- Apachefriends Xampp: up to and including 8.1.12
Published 2023-09-12. Last modified 2026-06-17.