PT-2026-39473 · Aerocms · Aerocms

Hubert Wojciechowski

·

Published

2026-05-10

·

Updated

2026-05-10

·

CVE-2022-50944

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Aero CMS version 0.0.1
Description An authenticated attacker can execute arbitrary PHP code by uploading malicious files. This is achieved by uploading PHP files containing embedded code to the 'admin posts.php' endpoint using the source=add post parameter via the image parameter.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2022-50944

Affected Products

Aerocms