NanoCMS 0.4 - Remote Code Execution (RCE) (Authenticated)
Vulnerability Description
NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated page content creation. Authenticated attackers can upload PHP files with arbitrary code to the server's pages directory by exploiting the page creation mechanism without proper input sanitization.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-50898
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- p1ckzi
Affected Vendor
kalyan02
View all reports →