CVE-2022-26986: SQL Injection
SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the sensitive information from the database used by the application. If misconfigured, an attacker can even upload a malicious web shell to compromise the entire system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-26986?
CVE-2022-26986 is classified as a critical vulnerability due to its potential to allow unauthorized access to sensitive database information.
How do I fix CVE-2022-26986?
To fix CVE-2022-26986, upgrade ImpressCMS to version 1.4.4 or later, which includes patches for this SQL injection vulnerability.
Who is affected by CVE-2022-26986?
CVE-2022-26986 affects all installations of ImpressCMS version 1.4.3 and earlier.
What kind of attacks can CVE-2022-26986 enable?
CVE-2022-26986 can enable remote attackers to read and modify sensitive information from the database, and potentially upload malicious web shells.
How does CVE-2022-26986 exploit SQL injection?
CVE-2022-26986 exploits SQL injection by allowing attackers to inject arbitrary SQL code into database queries, leading to unauthorized access and data manipulation.