CVE-2022-24977: Path Traversal
ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe interaction with the CKEditor processImage.php script. The payload may be placed in PHPSESSIONUPLOADPROGRESS when the PHP installation supports uploadprogress.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-24977?
CVE-2022-24977 is classified as a critical vulnerability due to its potential for unauthenticated remote code execution.
How do I fix CVE-2022-24977?
To remediate CVE-2022-24977, update ImpressCMS to version 1.4.2 or later.
What exposure does CVE-2022-24977 create for users?
CVE-2022-24977 allows attackers to execute arbitrary PHP code remotely by exploiting directory traversal vulnerabilities.
Which versions of ImpressCMS are affected by CVE-2022-24977?
CVE-2022-24977 affects all ImpressCMS versions prior to 1.4.2.
What kind of attack is facilitated by CVE-2022-24977?
CVE-2022-24977 facilitates remote code execution via unsafe interactions with the CKEditor processImage.php script.