PT-2026-2382 · E107 Cms · E107 Cms
Hubert Wojciechowski
·
Publicado
2026-01-13
·
Atualizado
2026-01-15
·
CVE-2022-50906
CVSS v3.1
4.8
Média
| Vetor | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
e107 CMS version 3.2.1
Description
An authenticated administrator can bypass upload restrictions in e107 CMS. This allows the upload of malicious SVG files through the media manager. Successful exploitation enables attackers to upload SVG files containing cross-site scripting (XSS) payloads. When viewed, these payloads can execute arbitrary scripts. The vulnerable functionality is related to file uploads via the media manager.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
E107 Cms