216.73.216.6

CVE-2021-47938

· Published 10/05/2026 13:16 · Modified 10/05/2026 13:16

Labels: CVE-2021-47938 2026-05-10CVE-2021-47938CWE-94[email protected]

Essential information

Published
10/05/2026 13:16
Modified
10/05/2026 13:16
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

ImpressCMS 1.4.2 contains a remote code execution vulnerability in the autotasks administrative interface that allows authenticated attackers to execute arbitrary PHP code by injecting malicious code into the sat_code parameter. Attackers can authenticate, submit a POST request to /modules/system/admin.php?fct=autotasks&op=mod with crafted sat_code containing PHP commands, which creates an executable file that accepts arbitrary commands via GET parameters.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
impresscms / impresscms cpe:2.3:a:impresscms:impresscms:1.4.2:*:*:*:*:*:*:*

References