LiveActive security incident?Get immediate response
CVE Record

CVE-2022-50916: e107 CMS v3.2.1 - Upload restriction bypass (Authenticated [Admin])+ Server file override

e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrators to override server files through the Media Manager import functionality. Attackers can exploit the upload mechanism by manipulating the upload URL parameter to overwrite existing files like top.php in the web application directory.

HighCVSS 8.7Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CVE-2022-50916 affects e107 CMS 3.2.1. An authenticated administrator can abuse the Media Manager import feature to overwrite server-side application files. This can damage site integrity or potentially enable deeper compromise. The main business risk is a compromised or misused admin account turning into full control over website files.

Executive priority

Treat as high priority for any internet-facing e107 CMS 3.2.1 site, especially where admin accounts are exposed or reused. This is less urgent for organizations without e107 CMS or with tightly controlled admin access, but validation should be quick because file overwrite can undermine website trust.

Technical view

The issue is a CWE-434 unrestricted upload/upload restriction bypass in e107 CMS 3.2.1. Sources describe manipulation of an upload URL parameter in Media Manager import to overwrite existing files, such as application files in the web directory. The provided CVSS v4.0 score is 8.7 high, with network access, low complexity, and low privileges required.

Likely exposure

Exposure appears limited to e107 CMS version 3.2.1 based on the provided sources. Risk is highest where CMS administrator accounts are numerous, weakly protected, externally accessible, or shared with third parties. No broader affected version range is provided in the source bundle.

Exploitation context

A public ExploitDB entry is listed, so defenders should assume technical details are available. The sources do not show CISA KEV listing or confirmed active exploitation. Exploitation requires authenticated administrative access according to the vulnerability description, reducing drive-by risk but increasing concern after credential compromise.

Researcher notes

The record names e107 CMS 3.2.1 and Media Manager import behavior, but the provided sources do not identify a vendor patch, fixed version, or affected-version range beyond 3.2.1. Avoid assuming active exploitation. Focus validation on version confirmation, admin exposure, file integrity, and vendor advisory tracking.

Mitigation direction

  • Confirm whether e107 CMS 3.2.1 is deployed; prioritize upgrades per vendor guidance.
  • Restrict CMS admin access to trusted networks and named administrators.
  • Review and reduce administrator privileges; remove dormant admin accounts.
  • Monitor webroot file integrity for unexpected changes to application files.
  • Back up site files and database before remediation.
  • Check e107 and VulnCheck pages for fixed-version guidance.

Validation and detection

  • Inventory e107 CMS instances and record exact version.
  • Review Media Manager import usage and administrative activity logs.
  • Check web application directories for unexpected overwritten core files.
  • Compare production files against trusted backups or vendor distribution.
  • Verify admin interfaces are not broadly reachable from the internet.
  • Document whether compensating controls limit authenticated admin access.
Prepared
Confidence
medium
Sources
6

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-434: File access and web shell behavior lookup

File traversal and upload weaknesses can lead teams to review file, web shell, execution, and collection telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

File access behavior lookup

The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2022-50916 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
8.7 (4.0)
Known Exploited
No
Published

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
5Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
8.7CVSS 4.0HighCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NPrimary CVE score

Vulnerability scoring details

Base CVSS 4.0 score

8.7High
CVSS 4.0 vector shape for CVE-2022-50916Attack VectorAttack ComplexityAttack RequirementsPrivileges RequiredUser InteractionVS ConfidentialityVS IntegrityVS AvailabilitySS ConfidentialitySS IntegritySS Availability

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Attack Requirements
NonePresent
Privileges Required
NoneLowHigh
User Interaction
NonePassiveActive
VS Confidentiality
HighLowNone
VS Integrity
HighLowNone
VS Availability
HighLowNone
SS Confidentiality
HighLowNone
SS Integrity
HighLowNone
SS Availability
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
e107e107 CMS3.2.1Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-434 · source CWE mapping

Unrestricted Upload of File with Dangerous Type

Unrestricted Upload of File with Dangerous Type represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.