PT-2026-2374 · Kalyan02 · Enano Cms
P1Ckzi
·
Published
2026-01-13
·
Updated
2026-01-13
·
CVE-2022-50898
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NanoCMS version 0.4
Description
An authenticated file upload issue allows remote code execution through unvalidated page content creation. Authenticated attackers can upload PHP files containing arbitrary code to the server's pages directory by exploiting the page creation mechanism, which lacks proper input sanitization.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Unrestricted File Upload
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Enano Cms