vendor:
ImpressCMS
by:
Sarang Tumne @CyberInsane
7.2
CVSS
HIGH
SQL Injection
89
CWE
Product Name: ImpressCMS
Affected Version From: 1.4.2003
Affected Version To: 1.4.2003
Patch Exists: YES
Related CWE: CVE-2022-26986
CPE: a:impresscms:impresscms:1.4.3
Platforms Tested:
2022
Authenticated Sql Injection in ImpressCMS v1.4.3
An authenticated SQL injection vulnerability exists in ImpressCMS v1.4.3. This vulnerability can be exploited by sending a malicious POST request to the vulnerable parameter 'mimetypeid' in the admin.php file. An attacker can use this vulnerability to execute arbitrary SQL commands on the vulnerable system.
Mitigation:
Upgrade to ImpressCMS v1.4.4 or later.