Executive brief
ImpressCMS is a PHP-based content management system. An authenticated administrator can inject and execute arbitrary PHP code by creating a malicious custom tag with PHP type enabled. The injected code runs automatically on every page load, allowing complete compromise of the website and server hosting it.
Technical details
This is a PHP code injection vulnerability in the custom tag module affecting ImpressCMS 2.0.3 and earlier. The vulnerable renderWithPhp() method in htdocs/modules/system/admin/customtag/class/customtag.php passes custom tag content to PHP's eval() function. Although HTML Purifier sanitizes the input, the undoHtmlSpecialChars() function decodes HTML entities back to plain characters before eval() executes, bypassing the sanitization. An authenticated administrator can create a PHP-type custom tag (customtag_type=3) containing malicious code, which is then stored in the database and executed on every frontend page load via the preload event system. No user interaction is required beyond administrator account access. Patches are available in versions after 2.0.3.
Affected products
- ImpressCMS ImpressCMS 2.0.3 and earlier
Timeline
- 2026-08-14: disclosed