CVE-2022-26986

SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the sensitive information from the database used by the application. If misconfigured, an attacker can even upload a malicious web shell to compromise the entire system.
Configurations

Configuration 1 (hide)

cpe:2.3:a:impresscms:impresscms:*:*:*:*:*:*:*:*

History

27 Mar 2023, 18:15

Type Values Removed Values Added
References
  • (MISC) http://packetstormsecurity.com/files/171485/ImpressCMS-1.4.3-SQL-Injection.html -

12 Apr 2022, 20:19

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 8.5
v3 : 7.2
CWE CWE-89
CPE cpe:2.3:a:impresscms:impresscms:*:*:*:*:*:*:*:*
References (MISC) https://github.com/sartlabs/0days/blob/main/ImpressCMS1.4.3/Exploit.txt - (MISC) https://github.com/sartlabs/0days/blob/main/ImpressCMS1.4.3/Exploit.txt - Exploit, Third Party Advisory

05 Apr 2022, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-04-05 15:15

Updated : 2024-02-04 22:29


NVD link : CVE-2022-26986

Mitre link : CVE-2022-26986

CVE.ORG link : CVE-2022-26986


JSON object : View

Products Affected

impresscms

  • impresscms
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')