TROYANOSYVIRUS
Back to CVEs

CVE-2022-50916

HIGH
7.2

Description

e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrators to override server files through the Media Manager import functionality. Attackers can exploit the upload mechanism by manipulating the upload URL parameter to overwrite existing files like top.php in the web application directory.

CVE Details

CVSS v3.1 Score7.2
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
Published1/13/2026
Last Modified1/16/2026
Sourcenvd
Honeypot Sightings0

Affected Products

e107:e107

Weaknesses (CWE)

CWE-434

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.