Remote Code Execution Vulnerability in Maccms 10 by Maccms
CVE-2019-9829
8.8HIGH
What is CVE-2019-9829?
Maccms 10 is susceptible to a remote code execution vulnerability, allowing attackers to execute arbitrary PHP code by manipulating template files. This occurs when the system processes user inputs in the template rendering phase, specifically during the Edit action of template/default_pc/html/art. By leveraging this flaw, malicious actors can circumvent security measures intended to block PHP file executions, leading to potentially severe impacts on application integrity and data security.
