CVE-2022-50916
HIGHe107 CMS <3.2.1 - File Upload
Title source: llmDescription
e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrators to override server files through the Media Manager import functionality. Attackers can exploit the upload mechanism by manipulating the upload URL parameter to overwrite existing files like top.php in the web application directory.
Exploits (1)
exploitdb
WORKING POC
by Hubert Wojciechowski · textwebappsphp
https://www.exploit-db.com/exploits/50910
Scores
CVSS v3
7.2
EPSS
0.0010
EPSS Percentile
28.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-434
Status
published
Products (2)
e107/e107
3.2.1
e107/e107 CMS
3.2.1
Published
Jan 13, 2026
Tracked Since
Feb 18, 2026