Description
BrainyCP 1.0 contains an authenticated remote code execution vulnerability that allows logged-in users to inject arbitrary commands through the crontab configuration interface. Attackers can exploit the crontab endpoint by adding a malicious command that spawns a reverse shell to a specified IP and port.
Problem types
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
Credits
Ahmet Ümit BAYRAM
References
www.exploit-db.com/exploits/51357
www.exploit-db.com/exploits/51357 (ExploitDB-51357)
brainycp.io (Official Product Homepage)
www.vulncheck.com/...-via-authenticated-crontab-manipulation (VulnCheck Advisory: BrainyCP 1.0 Remote Code Execution via Authenticated Crontab Manipulation)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.