CVE-2019-9829: High severity maccms vulnerability
Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a template/defaultpc/html/art Edit action. This occurs because template rendering uses an include operation on a cache file, which bypasses the prohibition of .php files as templates.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-9829?
CVE-2019-9829 is a vulnerability in Maccms 10 that allows remote attackers to execute arbitrary PHP code.
How does CVE-2019-9829 occur?
CVE-2019-9829 occurs because template rendering in Maccms 10 uses an include operation on a cache file, which bypasses the prohibition of .php files as templates.
What is the severity of CVE-2019-9829?
The severity of CVE-2019-9829 is high with a CVSS score of 8.8.
How can I exploit CVE-2019-9829?
To exploit CVE-2019-9829, enter arbitrary PHP code in the template/default_pc/html/art Edit action.
Is there a fix for CVE-2019-9829?
There is currently no known fix for CVE-2019-9829. It is recommended to update to a patched version of Maccms 10 when available.