NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated page content creation. Authenticated attackers can upload PHP files with arbitrary code to the server's pages directory by exploiting the page creation mechanism without proper input sanitization.
Metrics
Affected Vendors & Products
References
History
Wed, 14 Jan 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kalyan02
Kalyan02 nanocms |
|
| Vendors & Products |
Kalyan02
Kalyan02 nanocms |
Tue, 13 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated page content creation. Authenticated attackers can upload PHP files with arbitrary code to the server's pages directory by exploiting the page creation mechanism without proper input sanitization. | |
| Title | NanoCMS 0.4 - Remote Code Execution (RCE) (Authenticated) | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-13T22:51:44.934Z
Reserved: 2026-01-10T15:05:18.988Z
Link: CVE-2022-50898
No data.
Status : Awaiting Analysis
Published: 2026-01-13T23:15:51.833
Modified: 2026-01-14T16:25:12.057
Link: CVE-2022-50898
No data.