ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. Attackers can bypass file upload restrictions by using alternative file extensions .php2.php6.php7.phps.pht to execute arbitrary PHP code on the server.
Metrics
Affected Vendors & Products
References
History
Wed, 14 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 14 Jan 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Impresscms
Impresscms impresscms |
|
| Vendors & Products |
Impresscms
Impresscms impresscms |
Tue, 13 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. Attackers can bypass file upload restrictions by using alternative file extensions .php2.php6.php7.phps.pht to execute arbitrary PHP code on the server. | |
| Title | ImpressCMS 1.4.4 - Unrestricted File Upload | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-01-13T22:51:51.296Z
Updated: 2026-01-14T16:15:05.429Z
Reserved: 2026-01-11T13:14:18.876Z
Link: CVE-2022-50912
Updated: 2026-01-14T16:15:00.616Z
Status : Awaiting Analysis
Published: 2026-01-13T23:15:54.350
Modified: 2026-01-14T16:25:12.057
Link: CVE-2022-50912
No data.