CVE-2022-24977
Dashboard / Vulnerabilities / CVE-2022-24977
Summary:
Details: ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe interaction with the CKEditor processImage.php script. The payload may be placed in PHP_SESSION_UPLOAD_PROGRESS when the PHP installation supports upload_progress.
References: https://github.com/ImpressCMS/impresscms/compare/1.4.1...v1.4.2, https://r0.haxors.org/posts?id=8, https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24977.json, https://nvd.nist.gov/vuln/detail/CVE-2022-24977, https://github.com/ImpressCMS/impresscms/commit/a66d7bb499faafab803e24833606028fa0ba4261
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
v1.4.2
v1.4.2_rc
v1.4.0
v1.4.0-rc
v1.4.0-beta
v1.4.0-alpha.2
v1.4.0-alpha
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
