CVE-2021-47939
HIGHEvolution CMS 3.1.6 Authenticated Remote Code Execution via Module Creation
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47939. PoCs published by Halit AKAYDIN.
AI-analyzed exploit summary This exploit demonstrates an authenticated RCE vulnerability in Evolution CMS 3.1.6 by leveraging module creation functionality to execute arbitrary system commands. It authenticates as a privileged user, creates a malicious module, and executes commands via the 'post' parameter.
Description
Evolution CMS 3.1.6 contains a remote code execution vulnerability that allows authenticated users with module creation permissions to execute arbitrary system commands by injecting PHP code into module parameters. Attackers can send POST requests to /manager/index.php with malicious PHP code in the 'post' parameter to create modules that execute arbitrary commands when invoked.
Exploits (1)
This exploit demonstrates an authenticated RCE vulnerability in Evolution CMS 3.1.6 by leveraging module creation functionality to execute arbitrary system commands. It authenticates as a privileged user, creates a malicious module, and executes commands via the 'post' parameter.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H