Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-98vq-2fp5-cc8q

Опубликовано: 16 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 2
CVSS3: 4.7

Описание

A vulnerability was identified in CTCMS Content Management System up to 2.1.2. The affected element is the function Save of the file /ctcms/libs/Ct_App.php of the component Backend App Configuration Module. The manipulation of the argument CT_App_Paytype leads to code injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

A vulnerability was identified in CTCMS Content Management System up to 2.1.2. The affected element is the function Save of the file /ctcms/libs/Ct_App.php of the component Backend App Configuration Module. The manipulation of the argument CT_App_Paytype leads to code injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

EPSS

Процентиль: 17%
0.00053
Низкий

2 Low

CVSS4

4.7 Medium

CVSS3

Дефекты

CWE-74
CWE-94

Связанные уязвимости

CVSS3: 4.7
nvd
около 2 месяцев назад

A vulnerability was identified in CTCMS Content Management System up to 2.1.2. The affected element is the function Save of the file /ctcms/libs/Ct_App.php of the component Backend App Configuration Module. The manipulation of the argument CT_App_Paytype leads to code injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

EPSS

Процентиль: 17%
0.00053
Низкий

2 Low

CVSS4

4.7 Medium

CVSS3

Дефекты

CWE-74
CWE-94