CVE-2022-50898

NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated page content creation. Authenticated attackers can upload PHP files with arbitrary code to the server's pages directory by exploiting the page creation mechanism without proper input sanitization.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kalyan02:nanocms:0.4:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-13 23:15

Updated : 2026-01-29 14:16


NVD link : CVE-2022-50898

Mitre link : CVE-2022-50898

CVE.ORG link : CVE-2022-50898


JSON object : View

Products Affected

kalyan02

  • nanocms
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type