Aller au contenu

Fiche vulnérabilité

CVE-2022-26986 : vulnérabilité élevée (CVSS 7.2)

Description

SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the sensitive information from the database used by the application. If misconfigured, an attacker can even upload a malicious web shell to compromise the entire system.

En bref

Sévérité
Élevée (CVSS 7.2)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
5 avr. 2022
Dernière mise à jour
3 août 2024

Références

Rechercher une autre vulnérabilité dans la base CVE