74cms
cpe:2.3:a:74cms:74cms:*:*:*:*:*:*:*
- <= 3.33.0
A remote code execution vulnerability has been identified in 74cms versions through 3.33.0, specifically within the background interface apiadmin. The issue arises from the ability to upload and execute malicious packages on the server.
Exploitation of this vulnerability allows for remote code execution on the server where 74cms is installed.
To reproduce this vulnerability, access the apiadmin background interface. Although no official address is provided, any address can be entered to initiate a download. Afterward, upload a malicious package structured to exploit the vulnerability. The server will attempt to decompress the package, which may result in a decompression failure message that can be ignored. The exploitation involves sending a crafted HTTP GET request to the 'Upgrade/download' endpoint, followed by another request to the 'Upgrade/unzip' endpoint, both including the 'admintoken' for authentication.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.