High severity7.2NVD Advisory· Published Jan 13, 2026· Updated Jun 17, 2026
CVE-2022-50907
CVE-2022-50907
Description
e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrative users to bypass upload restrictions and execute PHP files. Attackers can upload malicious PHP files to parent directories by manipulating the upload URL parameter, enabling remote code execution through the Media Manager import feature.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
4- www.exploit-db.com/exploits/50910nvdExploitThird Party AdvisoryVDB Entry
- www.vulncheck.com/advisories/e-cms-admin-upload-restriction-bypass-rcenvdThird Party Advisory
- e107.orgnvdProduct
- e107.org/downloadnvdProduct
News mentions
0No linked articles in our index yet.