{"id":"CVE-2022-24977","aliases":["GHSA-389p-fchr-q2mg"],"url":"https://o3.security/vulnerability/CVE-2022-24977","summary":"Path Traversal in ImpressCMS","details":"ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe interaction with the CKEditor processImage.php script. The payload may be placed in PHP_SESSION_UPLOAD_PROGRESS when the PHP installation supports upload_progress.","published":"2022-02-13T06:39:33Z","modified":"2026-08-12T03:51:45.629151392Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.06354,"percentile":0.93199,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"impresscms/impresscms","fixedVersion":"1.4.2"}],"fix":{"url":"https://github.com/ImpressCMS/impresscms/commit/a66d7bb499faafab803e24833606028fa0ba4261","label":"ImpressCMS/impresscms@a66d7bb"},"references":[{"type":"WEB","url":"https://github.com/ImpressCMS/impresscms/compare/1.4.1...v1.4.2"},{"type":"WEB","url":"https://r0.haxors.org/posts?id=8"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24977.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24977"},{"type":"FIX","url":"https://github.com/ImpressCMS/impresscms/commit/a66d7bb499faafab803e24833606028fa0ba4261"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:45.629151392Z"}}