PT-2026-2363 · 4Images · 4Images

Andrey Stoykov

·

Publicado

2026-01-13

·

Atualizado

2026-02-02

·

CVE-2022-50806

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 4images version 1.9
Description The software contains a remote command execution issue. Authenticated administrators can inject reverse shell code through template editing functionality. Attackers can save malicious code in a template and execute arbitrary commands by accessing the ''/categories.php'' endpoint with a crafted cat id parameter.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the template editing functionality for administrators.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-RUM-2022-50806
CVE-2022-50806

Produtos afetados

4Images