Blackcat CMS 1.4 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the jquery plugin manager. Attackers can upload a zip file with a PHP shell script and execute arbitrary system commands by accessing the uploaded plugin's PHP file with a 'code' parameter.

Subscriptions

Vendors Products
Blackcat-cms Subscribe
Blackcat Cms Subscribe

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 17 Dec 2025 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:blackcat-cms:blackcat_cms:1.4:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Tue, 16 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Blackcat-cms
Blackcat-cms blackcat Cms
Vendors & Products Blackcat-cms
Blackcat-cms blackcat Cms

Mon, 15 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 15 Dec 2025 20:45:00 +0000

Type Values Removed Values Added
Description Blackcat CMS 1.4 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the jquery plugin manager. Attackers can upload a zip file with a PHP shell script and execute arbitrary system commands by accessing the uploaded plugin's PHP file with a 'code' parameter.
Title Blackcat CMS 1.4 Remote Code Execution via Jquery Plugin Manager
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-03-05T12:02:45.384Z

Reserved: 2025-12-15T14:39:05.361Z

Link: CVE-2023-53892

cve-icon Vulnrichment

Updated: 2025-12-15T21:37:09.632Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-15T21:15:52.537

Modified: 2025-12-17T15:37:00.730

Link: CVE-2023-53892

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-16T17:11:22Z

Weaknesses