← Back to CVEs
CVE-2022-50916
HIGH7.2
Description
e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrators to override server files through the Media Manager import functionality. Attackers can exploit the upload mechanism by manipulating the upload URL parameter to overwrite existing files like top.php in the web application directory.
CVE Details
CVSS v3.1 Score7.2
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
Published1/13/2026
Last Modified1/16/2026
Sourcenvd
Honeypot Sightings0
Affected Products
e107:e107
Weaknesses (CWE)
CWE-434
References
https://e107.org/(disclosure@vulncheck.com)
https://e107.org/download(disclosure@vulncheck.com)
https://www.exploit-db.com/exploits/50910(disclosure@vulncheck.com)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.