CyberRota Analysis
Saldırganın giriş yapmış olması gerekebilir. Uzaktan istismar edilebilir olabilir.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Detected Signals
remote code execution code execution
GitHub PoC Links
External Security References
Note: these links are listed for security research and verification purposes only.
CVE
CVE-2021-47939
Severity
HIGH
CVSS
8.8
EPSS
0.37%
Original NVD Description
Evolution CMS 3.1.6 contains a remote code execution vulnerability that allows authenticated users with module creation permissions to execute arbitrary system commands by injecting PHP code into module parameters. Attackers can send POST requests to /manager/index.php with malicious PHP code in the 'post' parameter to create modules that execute arbitrary commands when invoked.