PT-2026-2382 · E107 Cms · E107 Cms

Hubert Wojciechowski

·

Publicado

2026-01-13

·

Atualizado

2026-01-15

·

CVE-2022-50906

CVSS v3.1

4.8

Média

VetorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions e107 CMS version 3.2.1
Description An authenticated administrator can bypass upload restrictions in e107 CMS. This allows the upload of malicious SVG files through the media manager. Successful exploitation enables attackers to upload SVG files containing cross-site scripting (XSS) payloads. When viewed, these payloads can execute arbitrary scripts. The vulnerable functionality is related to file uploads via the media manager.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-50906

Produtos afetados

E107 Cms