Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Dogfood CRM Remote Command Execution Vulnerability in spell.php

Vulnerability

A remote command execution vulnerability has been identified in Dogfood CRM version 2.0.10. The issue resides in the spell.php script, which is part of the application's mail subsystem. The vulnerability is caused by unsanitized user input that is sent via a POST request to the data parameter. This input is processed by the underlying shell without proper escaping, allowing attackers to inject and execute arbitrary shell commands on the server. The vulnerability can be exploited without authentication.

Impact

Exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the server, potentially leading to a full system compromise.

Reproduction

To reproduce this vulnerability, send a POST request to the spell.php script with injected shell commands in the data parameter. The exploit is most effective using the double-reverse telnet payload, due to character restrictions that can interfere with command injection.

Added: Aug 30, 2025, 2:33 PM
Updated: Aug 30, 2025, 2:33 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
9.1
remediation
0.0
relevance
0.4
threat
9.3
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.