Exploitation Summary
EIP tracks 1 public exploit for CVE-2021-47938. PoCs published by Halit AKAYDIN.
AI-analyzed exploit summary This exploit leverages an authenticated RCE vulnerability in ImpressCMS 1.4.2 by abusing the autotasks feature to write a malicious PHP file (evil.php) to the server, which then allows arbitrary command execution via HTTP requests.
Description
ImpressCMS 1.4.2 contains a remote code execution vulnerability in the autotasks administrative interface that allows authenticated attackers to execute arbitrary PHP code by injecting malicious code into the sat_code parameter. Attackers can authenticate, submit a POST request to /modules/system/admin.php?fct=autotasks&op=mod with crafted sat_code containing PHP commands, which creates an executable file that accepts arbitrary commands via GET parameters.
Exploits (1)
This exploit leverages an authenticated RCE vulnerability in ImpressCMS 1.4.2 by abusing the autotasks feature to write a malicious PHP file (evil.php) to the server, which then allows arbitrary command execution via HTTP requests.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H