Record summary

CVE-2022-50912 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.

Description

ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. Attackers can bypass file upload restrictions by using alternative file extensions .php2.php6.php7.phps.pht to execute arbitrary PHP code on the server.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 14, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List1.4.4affected

Proofs of concept

1

Catalogued exploits

ExploitDBImpressCMS v1.4.4 - Unrestricted File UploadExploitDB exploitby Ünsal Furkan HaraniNot analyzed1 file
ExploitDB

PoC details

References

5