PT-2026-39513 · Impresscms · Impresscms

Halit Akaydin

·

Published

2026-05-10

·

Updated

2026-05-10

·

CVE-2021-47938

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ImpressCMS 1.4.2 contains a remote code execution vulnerability in the autotasks administrative interface that allows authenticated attackers to execute arbitrary PHP code by injecting malicious code into the sat code parameter. Attackers can authenticate, submit a POST request to /modules/system/admin.php?fct=autotasks&op=mod with crafted sat code containing PHP commands, which creates an executable file that accepts arbitrary commands via GET parameters.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2021-47938

Affected Products

Impresscms