Executive brief
Evolution CMS, a popular open-source content management system, contains a security flaw that allows certain authorized users to take full control of the web server. By creating a malicious module, an attacker with basic administrative permissions can execute arbitrary system commands. This could lead to a complete compromise of the website, theft of customer data, or a total service outage.
Technical details
A remote code execution (RCE) vulnerability exists in Evolution CMS 3.1.6 due to improper control of generation of code (CWE-94). Authenticated users who possess permissions to create or modify modules can inject malicious PHP code into module parameters via POST requests to /manager/index.php. Specifically, the 'post' parameter can be used to store arbitrary PHP code that is subsequently executed by the server when the module is invoked. This allows an attacker to bypass security restrictions and execute system-level commands with the privileges of the web server process. While the vulnerability requires authentication, it only requires low-level 'module creation' privileges rather than full site administrator access.
Affected products
- Evo Evolution CMS 3.1.6
Timeline
- 2021-09-15: disclosed: Exploit code published on Exploit-DB
- 2026-05-10: advisory: NVD publication date