74cms Remote Code Execution Vulnerability in Background Interface

Vulnerability

A remote code execution vulnerability has been identified in 74cms versions through 3.33.0, specifically within the background interface apiadmin. The issue arises from the ability to upload and execute malicious packages on the server.

Impact

Exploitation of this vulnerability allows for remote code execution on the server where 74cms is installed.

Reproduction

To reproduce this vulnerability, access the apiadmin background interface. Although no official address is provided, any address can be entered to initiate a download. Afterward, upload a malicious package structured to exploit the vulnerability. The server will attempt to decompress the package, which may result in a decompression failure message that can be ignored. The exploitation involves sending a crafted HTTP GET request to the 'Upgrade/download' endpoint, followed by another request to the 'Upgrade/unzip' endpoint, both including the 'admintoken' for authentication.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
10.0
exploitability
6.3
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.