Executive brief
Saurus CMS Community Edition, a content management system used for building and managing websites, contains a critical security flaw. An unauthenticated attacker can remotely execute malicious commands on the server by sending specially crafted web requests. This could result in a total compromise of the website, including the theft of sensitive customer data, website defacement, or the installation of ransomware.
Technical details
A critical vulnerability exists in Saurus CMS Community Edition 4.7.1 within the `DB::prepare()` function located in `classes/mysql.inc.php`. The function utilizes `preg_replace()` with the deprecated `/e` (eval) modifier to interpolate SQL query parameters. Because the replacement string is evaluated as PHP code and the parameter escaping is insufficient (vulnerable to multibyte charset bypasses like GBK), an unauthenticated attacker can inject arbitrary SQL statements. This flaw can be further leveraged to achieve arbitrary PHP code execution on the underlying server. The issue is particularly severe on older PHP environments where the `/e` modifier is still supported.
Affected products
- Saurus OÜ Saurus CMS Community Edition 4.7.1
Timeline
- 2025-08-15: disclosed: Vulnerability discovered and published by Rahul Hoysala
- 2025-08-19: advisory: CVE-2025-50567 published