Vendor
high
advisory
Authenticated RCE in ImpressCMS Custom Tag Module
1 TTP 1 CVEImpressCMS contains an authenticated remote code execution vulnerability (CVE-2026-73679) in the custom tag module, allowing administrators to execute arbitrary PHP code via improperly sanitized input.
ImpressCMS
1t
1c
high
advisory
ImpressCMS 1.4.2 Remote Code Execution via Autotasks Interface (CVE-2021-47938)
2 rules 2 TTPs 1 CVEImpressCMS 1.4.2 is vulnerable to remote code execution (RCE) via the autotasks administrative interface, where authenticated attackers can inject malicious PHP code into the sat_code parameter via a POST request to /modules/system/admin.php, leading to arbitrary PHP code execution through GET parameters (CVE-2021-47938).
ImpressCMS 1.4.2
code-injection
rce
impresscms
2r
2t
1c