CVE-2022-50907

HIGH

e107 CMS <3.2.1 - Authenticated RCE

Title source: llm

Description

e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrative users to bypass upload restrictions and execute PHP files. Attackers can upload malicious PHP files to parent directories by manipulating the upload URL parameter, enabling remote code execution through the Media Manager import feature.

Exploits (1)

exploitdb WORKING POC
by Hubert Wojciechowski · textwebappsphp
https://www.exploit-db.com/exploits/50910

Scores

CVSS v3 7.2
EPSS 0.0046
EPSS Percentile 64.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (2)
e107/e107 3.2.1
e107/e107 CMS 3.2.1
Published Jan 13, 2026
Tracked Since Feb 18, 2026