4images 1.9 - Remote Command Execution (RCE)
Vulnerability Description
4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attackers can save malicious code in the template and execute arbitrary commands by accessing a specific categories.php endpoint with a crafted cat_id parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-50806
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Andrey Stoykov
Affected Vendor
4Homepages
View all reports →