CVE-2022-50912
CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. Attackers can bypass file upload restrictions by using alternative file extensions .php2.php6.php7.phps.pht to execute arbitrary PHP code on the server.
Metadata
Severity & Metrics
9.8
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| ImpressCMS | ImpressCMS | — | 1.4.4 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-434 | cna | Unrestricted Upload of File with Dangerous Type |
CVSS scores (2)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 9.8 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 9.3 | CRITICAL | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
References (4)
- ExploitDB-50890 https://www.exploit-db.com/exploits/50890
- Official ImpressCMS Homepage https://www.impresscms.org/
- ImpressCMS GitHub Repository https://github.com/ImpressCMS/impresscms
- VulnCheck Advisory: ImpressCMS 1.4.4 - Unrestricted File Upload https://www.vulncheck.com/advisories/impresscms-unrestricted-file-upload