{"id":"CVE-2026-71232","published":"2026-08-05T11:16:25.873","lastModified":"2026-08-10T12:17:25.650","description":"MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function, register_tick_function, and error_log.","cvssScore":7.2,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-94"],"vendors":[],"products":[],"references":[{"url":"https://github.com/magicblack/maccms10/commit/71ad3bb29570e110d8e973acff68040a3050ddf0","tags":[]}],"exploitRefs":[{"url":"https://github.com/magicblack/maccms10/commit/71ad3bb29570e110d8e973acff68040a3050ddf0","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows execution of dangerous PHP functions in template content due to incomplete blacklist filtering, enabling remote code execution.","exploitability":"Exploitation requires access to the admin panel and knowledge of the affected version; moderate difficulty.","blast_radius":"If exploited, it could lead to full server compromise, data theft, or denial of service for MacCMS10 installations.","remediation":"Update to a patched version of MacCMS10 or apply custom filtering to block all dangerous PHP functions.","tags":["rce","web","php","admin-panel"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T07:02:54.314Z"}}