Junglewise Threat Intelligence

CVE-2025-50567: Saurus CMS Community Edition SQL injection and RCE in DB::prepare

CVE-2025-50567 · Severity: critical · CVSS 10 · Published 2025-08-19

Executive brief

Saurus CMS Community Edition, a content management system used for building and managing websites, contains a critical security flaw. An unauthenticated attacker can remotely execute malicious commands on the server by sending specially crafted web requests. This could result in a total compromise of the website, including the theft of sensitive customer data, website defacement, or the installation of ransomware.

Technical details

A critical vulnerability exists in Saurus CMS Community Edition 4.7.1 within the `DB::prepare()` function located in `classes/mysql.inc.php`. The function utilizes `preg_replace()` with the deprecated `/e` (eval) modifier to interpolate SQL query parameters. Because the replacement string is evaluated as PHP code and the parameter escaping is insufficient (vulnerable to multibyte charset bypasses like GBK), an unauthenticated attacker can inject arbitrary SQL statements. This flaw can be further leveraged to achieve arbitrary PHP code execution on the underlying server. The issue is particularly severe on older PHP environments where the `/e` modifier is still supported.

Affected products

  • Saurus OÜ Saurus CMS Community Edition 4.7.1

Timeline

  • 2025-08-15: disclosed: Vulnerability discovered and published by Rahul Hoysala
  • 2025-08-19: advisory: CVE-2025-50567 published

References