Описание
RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.
RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2025-67172
- https://github.com/handylulu/RiteCMS
- https://github.com/handylulu/RiteCMS/blob/master/cms/includes/functions.inc.php#L297
- https://github.com/handylulu/RiteCMS/blob/master/cms/includes/functions.inc.php#L504
- https://github.com/mbiesiad/vulnerability-research/tree/main/CVE-2025-67172
Связанные уязвимости
CVSS3: 7.2
nvd
около 2 месяцев назад
RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.