vendor:
Blackcat Cms
by:
Mirabbas Agalarov
9.8
CVSS
CRITICAL
Remote Code Execution (RCE)
94
CWE
Product Name: Blackcat Cms
Affected Version From: v1.4
Affected Version To: v1.4
Patch Exists: NO
Related CWE:
CPE: a:blackcat_development:blackcat_cms:1.4
Platforms Tested: Linux
2023
Blackcat Cms v1.4 – Remote Code Execution (RCE)
The Blackcat Cms v1.4 application is vulnerable to remote code execution (RCE) due to improper handling of user-supplied input. An attacker can upload a specially crafted ZIP file containing a malicious PHP file and execute arbitrary commands on the server.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of Blackcat Cms that addresses this issue. Additionally, ensure that user input is properly sanitized and validated before processing.