e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrators to override server files through the Media Manager import functionality. Attackers can exploit the upload mechanism by manipulating the upload URL parameter to overwrite existing files like top.php in the web application directory.
Metrics
Affected Vendors & Products
References
History
Tue, 13 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrators to override server files through the Media Manager import functionality. Attackers can exploit the upload mechanism by manipulating the upload URL parameter to overwrite existing files like top.php in the web application directory. | |
| Title | e107 CMS v3.2.1 - Upload restriction bypass (Authenticated [Admin])+ Server file override | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-13T22:51:52.935Z
Reserved: 2026-01-11T13:14:18.877Z
Link: CVE-2022-50916
No data.
Status : Received
Published: 2026-01-13T23:15:55.073
Modified: 2026-01-13T23:15:55.073
Link: CVE-2022-50916
No data.
OpenCVE Enrichment
No data.