nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25687 CVE-2019-25687
CRITICAL
Pegasus CMS 1.0 Remote Code Execution via extra_fields.php
Record summary
CVE-2019-25687 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.
Description
Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticated attackers to execute arbitrary commands by exploiting unsafe eval functionality. Attackers can send POST requests to the submit.php endpoint with malicious PHP code in the action parameter to achieve code execution and obtain an interactive shell.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Pegasus CMSBrowse wisdom / Pegasus CMS | CVE List | 1.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBPegasus CMS 1.0 - 'extra_fields.php' Plugin Remote Code ExecutionExploitDB exploitby R3zk0nNot analyzed1 file
References
4ExploitDB-46542exploit
https://www.exploit-db.com/exploits/46542 VulnCheck Advisory: Pegasus CMS 1.0 Remote Code Execution via extra_fields.phpThird-party advisory
https://www.vulncheck.com/advisories/pegasus-cms-remote-code-execution-via-extra-fields-php Official Product Homepageproduct
https://www.wisdom.com.au/web/pegasus-cms