SQL Injection Vulnerability in ImpressCMS by Sartlabs
CVE-2022-26986
7.2HIGH
What is CVE-2022-26986?
ImpressCMS versions 1.4.3 and earlier are susceptible to SQL Injection, which allows remote attackers to manipulate database queries. This vulnerability can lead to unauthorized access to sensitive information, enabling attackers to read and modify data within the database. In scenarios where the application is improperly configured, there is potential for attackers to upload malicious web shells, further compromising the system and escalating the impact of the breach.
