Remote Code Execution Vulnerability in MacCMS10 by MagicBlack
CVE-2026-71232
7.2HIGH
What is CVE-2026-71232?
The vulnerability in MacCMS10's admin template editor arises from an inadequate filter that fails to block critical PHP functions such as exec and passthru. This oversight allows an authenticated administrator to exploit the system by injecting malicious payloads within template conditions using ThinkPHP's template tag system. With the ability to execute commands on the server, attackers can potentially gain full control over the affected environment. A fix has been implemented to address these filtering deficiencies, ensuring a more secure template handling process.
Affected Version(s)
maccms10 0 < 10
