Security readout for executives and security teams
Plain-English summary
CVE-2022-50916 affects e107 CMS 3.2.1. An authenticated administrator can abuse the Media Manager import feature to overwrite server-side application files. This can damage site integrity or potentially enable deeper compromise. The main business risk is a compromised or misused admin account turning into full control over website files.
Executive priority
Treat as high priority for any internet-facing e107 CMS 3.2.1 site, especially where admin accounts are exposed or reused. This is less urgent for organizations without e107 CMS or with tightly controlled admin access, but validation should be quick because file overwrite can undermine website trust.
Technical view
The issue is a CWE-434 unrestricted upload/upload restriction bypass in e107 CMS 3.2.1. Sources describe manipulation of an upload URL parameter in Media Manager import to overwrite existing files, such as application files in the web directory. The provided CVSS v4.0 score is 8.7 high, with network access, low complexity, and low privileges required.
Likely exposure
Exposure appears limited to e107 CMS version 3.2.1 based on the provided sources. Risk is highest where CMS administrator accounts are numerous, weakly protected, externally accessible, or shared with third parties. No broader affected version range is provided in the source bundle.
Exploitation context
A public ExploitDB entry is listed, so defenders should assume technical details are available. The sources do not show CISA KEV listing or confirmed active exploitation. Exploitation requires authenticated administrative access according to the vulnerability description, reducing drive-by risk but increasing concern after credential compromise.
Researcher notes
The record names e107 CMS 3.2.1 and Media Manager import behavior, but the provided sources do not identify a vendor patch, fixed version, or affected-version range beyond 3.2.1. Avoid assuming active exploitation. Focus validation on version confirmation, admin exposure, file integrity, and vendor advisory tracking.
Mitigation direction
- Confirm whether e107 CMS 3.2.1 is deployed; prioritize upgrades per vendor guidance.
- Restrict CMS admin access to trusted networks and named administrators.
- Review and reduce administrator privileges; remove dormant admin accounts.
- Monitor webroot file integrity for unexpected changes to application files.
- Back up site files and database before remediation.
- Check e107 and VulnCheck pages for fixed-version guidance.
Validation and detection
- Inventory e107 CMS instances and record exact version.
- Review Media Manager import usage and administrative activity logs.
- Check web application directories for unexpected overwritten core files.
- Compare production files against trusted backups or vendor distribution.
- Verify admin interfaces are not broadly reachable from the internet.
- Document whether compensating controls limit authenticated admin access.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-434: File access and web shell behavior lookup
File traversal and upload weaknesses can lead teams to review file, web shell, execution, and collection telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupFile access behavior lookup
The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2022-50916 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 8.7 (4.0)
- Known Exploited
- No
- Published
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N——Primary CVE scoreVulnerability scoring details
Base CVSS 4.0 score
8.7HighVector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source materials
- CVE List V5 sourceCVE List V5
- ExploitDB-50910CVE reference · exploit
- Official Vendor HomepageCVE reference · product
- Software Download PageCVE reference · product
- VulnCheck Advisory: e107 CMS v3.2.1 - Upload restriction bypass (Authenticated [Admin])+ Server file overrideCVE reference · third-party-advisory
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Unrestricted Upload of File with Dangerous Type
Unrestricted Upload of File with Dangerous Type represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
