PT-2026-2363 · 4Images · 4Images

Andrey Stoykov

·

Published

2026-01-13

·

Updated

2026-02-02

·

CVE-2022-50806

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 4images version 1.9
Description The software contains a remote command execution issue. Authenticated administrators can inject reverse shell code through template editing functionality. Attackers can save malicious code in a template and execute arbitrary commands by accessing the ''/categories.php'' endpoint with a crafted cat id parameter.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the template editing functionality for administrators.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

BIT-RUM-2022-50806
CVE-2022-50806

Affected Products

4Images