CVE-2022-50893 PUBLISHED

VIAVIWEB Wallpaper Admin 1.0 - Code Execution via Image Upload

Assigner: VulnCheck
Reserved: 10.01.2026 Published: 13.01.2026 Updated: 14.01.2026

VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functionality. Attackers can upload a malicious PHP file through the add_gallery_image.php endpoint to execute arbitrary code on the server.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor VIAVIWEB
Product VIAVIWEB Wallpaper Admin
Versions
  • Version 1.0 is affected

Credits

  • [Edd13Mora] finder

References

Problem Types

  • Unrestricted Upload of File with Dangerous Type CWE