PT-2026-2382 · E107 Cms · E107 Cms

Hubert Wojciechowski

·

Published

2026-01-13

·

Updated

2026-01-15

·

CVE-2022-50906

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions e107 CMS version 3.2.1
Description An authenticated administrator can bypass upload restrictions in e107 CMS. This allows the upload of malicious SVG files through the media manager. Successful exploitation enables attackers to upload SVG files containing cross-site scripting (XSS) payloads. When viewed, these payloads can execute arbitrary scripts. The vulnerable functionality is related to file uploads via the media manager.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-50906

Affected Products

E107 Cms