NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated page content creation. Authenticated attackers can upload PHP files with arbitrary code to the server's pages directory by exploiting the page creation mechanism without proper input sanitization.
References
| Link | Resource |
|---|---|
| https://github.com/ishell/Exploits-Archives/blob/master/2009-exploits/0904-exploits/nanocms-multi.txt | Third Party Advisory |
| https://github.com/kalyan02/NanoCMS | Product |
| https://www.exploit-db.com/exploits/50997 | Exploit |
| https://www.vulncheck.com/advisories/nanocms-remote-code-execution-rce-authenticated | Third Party Advisory |
| https://github.com/ishell/Exploits-Archives/blob/master/2009-exploits/0904-exploits/nanocms-multi.txt | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-01-13 23:15
Updated : 2026-01-29 14:16
NVD link : CVE-2022-50898
Mitre link : CVE-2022-50898
CVE.ORG link : CVE-2022-50898
JSON object : View
Products Affected
kalyan02
- nanocms
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
