Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xj9j-gjxg-7jvq

Опубликовано: 25 нояб. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

REDAXO CMS is vulnerable to RCE attack through its template management component

A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbitrary operating system commands by injecting PHP code into an active template. The payload is executed when visitors access frontend pages using the compromised template.

Пакеты

Наименование

redaxo/source

composer
Затронутые версииВерсия исправления

< 5.20.1

5.20.1

EPSS

Процентиль: 65%
0.00493
Низкий

7.2 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.2
nvd
3 месяца назад

A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbitrary operating system commands by injecting PHP code into an active template. The payload is executed when visitors access frontend pages using the compromised template.

EPSS

Процентиль: 65%
0.00493
Низкий

7.2 High

CVSS3

Дефекты

CWE-94