PT-2026-47030 · Hax Cms · Hax Cms
CVE-2026-46394
·
Published
2026-06-05
·
Updated
2026-06-06
CVSS v4.0
7.7
High
| Vector | AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
HAX CMS versions prior to 26.0.0
Description
An OS command injection issue exists in the Git.php library of the PHP backend. The application executes shell command strings using the
proc open() function without properly sanitizing input. An attacker capable of controlling parameters passed into Git operations can execute arbitrary OS commands with web server privileges. Of the 17 functions that invoke shell commands, only the commit() function correctly utilizes escapeshellarg(). If combined with a configuration manipulation flaw, this can result in full remote code execution and complete system compromise.Recommendations
Update to version 26.0.0.
Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hax Cms