CVE-2019-25687
CRITICALPegasus CMS 1.0 Remote Code Execution via extra_fields.php
Title source: cnaDescription
Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticated attackers to execute arbitrary commands by exploiting unsafe eval functionality. Attackers can send POST requests to the submit.php endpoint with malicious PHP code in the action parameter to achieve code execution and obtain an interactive shell.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.0098
EPSS Percentile
76.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-22
Status
published
Products (1)
wisdom/Pegasus CMS
1.0
Published
Apr 05, 2026
Tracked Since
Apr 06, 2026