CVE-2020-25538
HIGHCMSuno 1.6.2 - Authenticated Remote Code Execution via Lang Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-25538.
AI-analyzed exploit summary This Ruby script exploits an authenticated remote code execution vulnerability in CMSUno 1.6.1 and 1.6.2 by injecting malicious payloads into the 'user' or 'lang' parameters during password update requests. It handles authentication, anti-CSRF tokens, and command execution via system calls.
Description
An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web page. In this way, attacker can takeover the control of the server.
Exploits (1)
This Ruby script exploits an authenticated remote code execution vulnerability in CMSUno 1.6.1 and 1.6.2 by injecting malicious payloads into the 'user' or 'lang' parameters during password update requests. It handles authentication, anti-CSRF tokens, and command execution via system calls.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H