CVE-2022-26986

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-26986
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-26986.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-26986
Aliases
Published
2022-04-05T15:15:08Z
Modified
2024-05-14T11:44:50.987746Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the sensitive information from the database used by the application. If misconfigured, an attacker can even upload a malicious web shell to compromise the entire system.

References

Affected packages

Git / github.com/impresscms/impresscms

Affected ranges

Type
GIT
Repo
https://github.com/impresscms/impresscms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

1.*

1.3.10-beta
1.3.8
1.3.8-beta
1.3.9
1.3.9_rc
1.4.1

impresscms_1.*

impresscms_1.3.3
impresscms_1.3.4

v1.*

v1.3.10
v1.3.11
v1.3.11-beta
v1.3.11-beta2
v1.3.11-rc
v1.3.11-rc2
v1.3.8
v1.4.0
v1.4.0-alpha
v1.4.0-alpha.2
v1.4.0-beta
v1.4.0-rc
v1.4.1_beta
v1.4.2
v1.4.2_bis
v1.4.2_rc
v1.4.3
v1.4.3-rc
v1.4.3-rc2