Executive brief
RooCMS is a content management system used to build and manage websites. A code injection vulnerability in the frontend rendering component allows remote attackers to execute arbitrary code on the server by manipulating content arguments, potentially leading to full server compromise and data theft.
Technical details
A code injection flaw exists in the eval function of roocms/site_pagePHP.php's frontend rendering component. The vulnerability stems from insufficient sanitization of the content parameter, allowing an unauthenticated remote attacker to inject and execute arbitrary PHP code with no user interaction required.
Affected products
- RooCMS RooCMS up to 1.2.2, 1.3.4, and 1.4RC2
Timeline
- 2026-09-21: disclosed