CVE-2022-50912: ImpressCMS 1.4.4 - Unrestricted File Upload
ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. Attackers can bypass file upload restrictions by using alternative file extensions .php2.php6.php7.phps.pht to execute arbitrary PHP code on the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-50912?
CVE-2022-50912 has a high severity due to its unrestricted file upload vulnerability that can lead to arbitrary code execution.
How do I fix CVE-2022-50912?
To fix CVE-2022-50912, update ImpressCMS to the latest version where the file upload vulnerability has been addressed.
What types of files can be uploaded due to CVE-2022-50912?
CVE-2022-50912 allows attackers to upload files with weakly sanitized extensions like .php2, .php6, .php7, and .phps.
Can CVE-2022-50912 be exploited remotely?
Yes, CVE-2022-50912 can be exploited remotely by attackers to upload malicious files to the server.
Which version of ImpressCMS is affected by CVE-2022-50912?
CVE-2022-50912 affects ImpressCMS version 1.4.4.