Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r2jm-vp5j-vxhh

Опубликовано: 14 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.8

Описание

4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attackers can save malicious code in the template and execute arbitrary commands by accessing a specific categories.php endpoint with a crafted cat_id parameter.

4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attackers can save malicious code in the template and execute arbitrary commands by accessing a specific categories.php endpoint with a crafted cat_id parameter.

EPSS

Процентиль: 50%
0.00267
Низкий

8.6 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.8
nvd
25 дней назад

4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attackers can save malicious code in the template and execute arbitrary commands by accessing a specific categories.php endpoint with a crafted cat_id parameter.

EPSS

Процентиль: 50%
0.00267
Низкий

8.6 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-94