CVE-2026-5333: DefaultFuction Content-Management-System tools.php command injection
A security flaw has been discovered in DefaultFuction Content-Management-System 1.0. This issue affects some unknown processing of the file /admin/tools.php. The manipulation of the argument host results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5333?
The severity of CVE-2026-5333 is medium, rated at 6.9.
How does CVE-2026-5333 manifest in DefaultFuction Content-Management-System?
CVE-2026-5333 manifests as a command injection vulnerability through improper handling of the argument host in /admin/tools.php.
Can CVE-2026-5333 be exploited remotely?
Yes, CVE-2026-5333 can be exploited remotely.
What is the recommendation to mitigate CVE-2026-5333?
The recommended mitigation for CVE-2026-5333 is to patch the DefaultFuction Content-Management-System to the latest version to address the vulnerability.
What type of attack is associated with CVE-2026-5333?
CVE-2026-5333 is associated with command injection attacks.