CVE-2022-50906: e107 CMS v3.2.1 - Admin Upload Restriction Bypass + Stored XSS
e107 CMS 3.2.1 contains an upload restriction bypass vulnerability that allows authenticated administrators to upload malicious SVG files through the media manager. Attackers with admin privileges can exploit this vulnerability to upload SVG files with embedded cross-site scripting (XSS) payloads that can execute arbitrary scripts when viewed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-50906?
CVE-2022-50906 has a high severity rating due to its potential for allowing malicious SVG file uploads by authenticated administrators.
How do I fix CVE-2022-50906?
To fix CVE-2022-50906, ensure that your e107 CMS is updated to the latest version that addresses this vulnerability.
Who is affected by CVE-2022-50906?
CVE-2022-50906 affects users of e107 CMS version 3.2.1 and potentially earlier versions.
What type of attacks can CVE-2022-50906 facilitate?
CVE-2022-50906 can facilitate uploaded file attacks allowing authenticated users to exploit vulnerabilities related to SVG files.
Is CVE-2022-50906 easy to exploit?
Yes, CVE-2022-50906 is considered relatively easy to exploit for anyone with administrative privileges.