PT-2026-68098 · Maccms10 · Maccms10

·

CVE-2026-71232

·

Published

2026-08-05

·

Updated

2026-08-10

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MacCMS10 (affected versions not specified)
Description The admin template editor in application/admin/controller/Template.php uses a blacklist regex to block dangerous PHP functions in template content. However, the blacklist fails to include exec, passthru, popen, show source, create function, register shutdown function, register tick function, and error log. An authenticated administrator can exploit this by using the ThinkPHP {if} template tag, which embeds the condition attribute directly into raw PHP, allowing for remote code execution.
Recommendations Apply the fix provided in commit 71ad3bb29570e110d8e973acff68040a3050ddf0 to update the function filter.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71232

Affected Products

Maccms10