CVE-2022-26986
Estado: ModificadaAlta (7.2)—💥 Exploit
SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the sensitive information from the database used by the application. If misconfigured, an attacker can even upload a malicious web shell to compromise the entire system.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 4.13%
- Percentil entre todas las CVEs puntuadas: 91
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Publicado en Exploit-DB · ImpressCMS v1.4.3 - Authenticated SQL Injection (25/3/2023)
Tecnologías afectadas (1)
CWE
- CWE-89
Referencias
- http://packetstormsecurity.com/files/171485/ImpressCMS-1.4.3-SQL-Injection.html
- https://github.com/sartlabs/0days/blob/main/ImpressCMS1.4.3/Exploit.txt
- http://packetstormsecurity.com/files/171485/ImpressCMS-1.4.3-SQL-Injection.html
- https://github.com/sartlabs/0days/blob/main/ImpressCMS1.4.3/Exploit.txt
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-26986",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 8.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:C/I:C/A:C",
"authentication": "SINGLE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.2,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.2
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2022-04-05T15:15:08.597",
"references": [
{
"url": "http://packetstormsecurity.com/files/171485/ImpressCMS-1.4.3-SQL-Injection.html",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/sartlabs/0days/blob/main/ImpressCMS1.4.3/Exploit.txt",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://packetstormsecurity.com/files/171485/ImpressCMS-1.4.3-SQL-Injection.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/sartlabs/0days/blob/main/ImpressCMS1.4.3/Exploit.txt",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the sensitive information from the database used by the application. If misconfigured, an attacker can even upload a malicious web shell to compromise the entire system."
},
{
"lang": "es",
"value": "Una inyección SQL en ImpressCMS versiones 1.4.3 y anteriores, permite a atacantes remotos inyectar en el código de forma no intencionada, esto permite a un atacante leer y modificar la información confidencial de la base de datos utilizada por la aplicación. Si es configurada inapropiadamente, un atacante puede incluso cargar una shell web maliciosa para comprometer todo el sistema"
}
],
"lastModified": "2026-06-17T04:36:15.937",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:impresscms:impresscms:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "50AAF76B-773D-4011-A958-2EF994347075",
"versionEndIncluding": "1.4.3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}