Impact
A vulnerability has been identified in GreenCMS in the pluginAddLocal routine of the index.php module used for adding local plugins. The flaw allows an attacker to upload arbitrary files without any verification of file type or access control. This can enable the placement of malicious scripts or other executable content, potentially leading to remote code execution or modification of site content. The weakness is classified as CWE-284 and CWE-434.
Affected Systems
The vulnerability affects GreenCMS versions up to 2.3, which are no longer supported by the maintainer. These releases contain the flaw, but no further security updates are released. Any deployment of these legacy versions, especially those exposed to the Internet, is at risk.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity, but the EPSS score is below 1 % and the flaw is not listed in the CISA KEV catalog, suggesting exploitation is unlikely in the near term. Nevertheless, the attack can be launched remotely via the public pluginAddLocal endpoint, and the lack of ongoing support for affected versions further raises the risk of unpatched or misconfigured deployments.
OpenCVE Enrichment