CVE-2023-53892
15.12.2025, 21:15
Blackcat CMS 1.4 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the jquery plugin manager. Attackers can upload a zip file with a PHP shell script and execute arbitrary system commands by accessing the uploaded plugin's PHP file with a 'code' parameter.Enginsight
| Vendor | Product | Version |
|---|---|---|
| blackcat-cms | blackcat_cms | 1.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration