CVE-2022-50944Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Aero CMS 0.0.1 contains a PHP code injection vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious files through the image parameter. Attackers can upload PHP files with embedded code to the admin posts.php endpoint with source=add_post parameter, and the uploaded files are executed by the server.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-10: 3Technical Details · 2026-05-10: 305-10
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Full discourse3 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 High - Aero CMS PHP Code Injection (CVE-2022-50944) Aero CMS 0.0.1 contains a PHP code injection vulnerability that allows authenticated attackers to execute arbitrary code. By uploading malicious PHP files via the image parameter in the posts.php endpoint, an attacker can trigger execution on the server, leading to full system compromise. 👉 Affected: Aero CMS 0.0.1

    Post summary

    Aero CMS 0.0.1 suffers from a PHP code injection flaw via the image parameter that allows authenticated users to upload malicious PHP files, enabling arbitrary code execution and full system compromise.

    0000057
    176 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2022-50944 Aero CMS 0.0.1 contains a PHP code injection vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious files through the … https://www.cve.org/CVERecord?id=CVE-2022-50944

    Post summary

    The text announces a PHP code injection flaw in Aero CMS v0.0.1 that lets authenticated users run arbitrary PHP code via malicious file uploads, as documented in the CVE record.

    0000093
    57.5K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2022-50944 Aero CMS 0.0.1 contains a PHP code injection vulnerability that allows authenticated attackers to execute arbitrary PHP… CVSS 8.8 Full analysis → https://sec.kaitan.id/cves/CVE-2022-50944 #HP #CyberSecurity #InfoSec

    Post summary

    The post discloses CVE-2022-50944, describing a PHP code injection flaw in Aero CMS 0.0.1 that allows authenticated attackers to execute arbitrary PHP, with a CVSS score of 8.8.

    0000029
    90 followersView on X

Explore more