PT-2026-96022 · Roocms · Roocms
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:L/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
RooCMS versions 1.2.2 and earlier
RooCMS versions 1.3.4 and earlier
RooCMS versions 1.4RC2 and earlier
Description
A code injection issue exists in the Frontend Rendering component within the
eval() function of the roocms/site pagePHP.php file. A remote attacker can exploit this by manipulating the content argument to execute arbitrary code.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the
roocms/site pagePHP.php file or disable the eval() function within that component to minimize the risk of exploitation.Exploit
Special Elements Injection
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Roocms