CVE-2020-25557
HIGHCMSuno 1.6.2 - Authenticated Remote Code Execution via Username Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-25557. PoCs published by Alexandre ZANNI.
AI-analyzed exploit summary This Ruby script exploits an authenticated remote code execution vulnerability in CMSUno 1.6.1 and 1.6.2 by injecting malicious payloads into the 'user' or 'lang' parameters. It handles authentication, anti-CSRF tokens, and command execution via system calls.
Description
In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs in to the application, attacker's code will be run. As a result of this vulnerability, authenticated user can run command on the server.
Exploits (1)
This Ruby script exploits an authenticated remote code execution vulnerability in CMSUno 1.6.1 and 1.6.2 by injecting malicious payloads into the 'user' or 'lang' parameters. It handles authentication, anti-CSRF tokens, and command execution via system calls.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H