8.5
CVSSv2

CVE-2022-26986

Published: 05/04/2022 Updated: 27/03/2023
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 756
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

SQL Injection in ImpressCMS 1.4.3 and previous versions allows remote malicious users to inject into the code in unintended way, this allows an malicious user to read and modify the sensitive information from the database used by the application. If misconfigured, an attacker can even upload a malicious web shell to compromise the entire system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

impresscms impresscms