EIP-2026-105414
PRE-CVEBatflat CMS 1.3.6 - Remote Code Execution (Authenticated)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-105414. PoCs published by mari0x00.
AI-analyzed exploit summary This exploit leverages an authenticated RCE vulnerability in Batflat CMS <= 1.3.6 by injecting a PHP reverse shell payload into the 'fullname' field during user creation. The payload triggers when the user management page is accessed, establishing a reverse shell to the attacker's specified IP and port.
Description
Batflat CMS 1.3.6 - Remote Code Execution (Authenticated)
Exploits (1)
This exploit leverages an authenticated RCE vulnerability in Batflat CMS <= 1.3.6 by injecting a PHP reverse shell payload into the 'fullname' field during user creation. The payload triggers when the user management page is accessed, establishing a reverse shell to the attacker's specified IP and port.