Description
A vulnerability was detected in iCMS up to 8.0.0. Affected is the function Save of the file app/config/ConfigAdmincp.php of the component POST Parameter Handler. The manipulation of the argument config results in code injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Problem types
Timeline
| 2025-12-31: | Advisory disclosed |
| 2025-12-31: | VulDB entry created |
| 2025-12-31: | VulDB entry last update |
Credits
hiro (VulDB User)
References
vuldb.com/?id.339163 (VDB-339163 | iCMS POST Parameter ConfigAdmincp.php save code injection)
vuldb.com/?ctiid.339163 (VDB-339163 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.719029 (Submit #719029 | ICMS https://www.icmsdev.com/ 8.0.0 Code Injection)
note-hxlab.wetolink.com/share/QWuWZeAmzUdm
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.