CVE-2022-24977
ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe interaction with the CKEditor processImage.php script.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.35%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe interaction with the CKEditor processImage.php script. The payload may be placed in PHP_SESSION_UPLOAD_PROGRESS when the PHP installation supports upload_progress.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 6.35% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- impresscms/impresscms
- Source
- cve@mitre.org
References
- https://github.com/ImpressCMS/impresscms/commit/a66d7bb499faafab803e24833606028fa0ba4261Patch, Third Party Advisory
- https://github.com/ImpressCMS/impresscms/compare/1.4.1...v1.4.2Patch, Third Party Advisory
- https://r0.haxors.org/posts?id=8Exploit, Third Party Advisory
- https://github.com/ImpressCMS/impresscms/commit/a66d7bb499faafab803e24833606028fa0ba4261Patch, Third Party Advisory
- https://github.com/ImpressCMS/impresscms/compare/1.4.1...v1.4.2Patch, Third Party Advisory
- https://r0.haxors.org/posts?id=8Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.