CVE-2022-24977
9.8
CRITICAL · CVSS 3.1 · EPSS 6.4% (pctl 93)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe interaction with the CKEditor processImage.php script. The payload may be placed in PHP_SESSION_UPLOAD_PROGRESS when the PHP installation supports upload_progress.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.35% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-02-14 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| impresscms | impresscms |
References
- https://github.com/ImpressCMS/impresscms/commit/a66d7bb499faafab803e24833606028fa0ba4261
- https://github.com/ImpressCMS/impresscms/compare/1.4.1...v1.4.2
- https://r0.haxors.org/posts?id=8
- https://github.com/ImpressCMS/impresscms/commit/a66d7bb499faafab803e24833606028fa0ba4261
- https://github.com/ImpressCMS/impresscms/compare/1.4.1...v1.4.2
- https://r0.haxors.org/posts?id=8
→ the Explorer · watch your stack · NVD