Skip to content
CVE-2021-47938 - Exploits & Severity

CVE-2021-47938 - Exploits & Severity

Feedly May 10, 2026

ImpressCMS 1.4.2 contains a remote code execution vulnerability in the autotasks administrative interface. Authenticated attackers can inject malicious PHP code into the sat_code parameter by submitting a POST request to /modules/system/admin.php?fct=autotasks&op=mod, which creates an executable file that accepts arbitrary commands via GET parameters.

An authenticated user with administrative access can execute arbitrary PHP code and commands on the server with the privileges of the web application process, allowing complete system compromise.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Patch is available via Github Advisory (GHSA-5fc9-c3p9-h598).

Apply the available patch immediately. Additionally, restrict access to the autotasks administrative interface to trusted administrators only, monitor POST requests to /modules/system/admin.php for suspicious sat_code parameters, and implement code review processes for any custom autotasks before deployment.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

NVD published the first details for CVE-2021-47938

A CVSS base score of 8.8 has been assigned.

Feedly found the first article mentioning CVE-2021-47938 . See article

GitHub Advisories released a security advisory .

CVE-2021-47938 - ImpressCMS 1.4.2 Remote Code Execution via Autotasks CVE ID : CVE-2021-47938 Published : May 10, 2026, 1:16 p.m. | 3 hours, 9 minutes ago Description : ImpressCMS 1.4.2 contains a remote code execution vulnerability in the autotasks administrative interf...

CVE Alert: CVE-2021-47938 - Impresscms - ImpressCMS - RedPacket Security

CVE-2021-47938 | ImpressCMS 1.4.2 Autotasks Administrative Interface admin.php?fct=autotasks&op=mod sat_code code injection (Exploit 50298 / EDB-50298)

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities