Impact
The issue in esoTalk version 1.0.0g4 allows a remote attacker to execute arbitrary server‑side PHP code through the core/models/ETMemberModel.class.php, core/controllers/ETMemberController.class.php, and core/lib/ET.class.php components. This vulnerability gives the attacker the ability to run arbitrary PHP code on the host running the application, effectively granting full control over the affected application.
Affected Systems
esoTalk forum software version 1.0.0g4, specifically the core/models/ETMemberModel.class.php, core/controllers/ETMemberController.class.php, and core/lib/ET.class.php components.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in CISA KEV. The CVSS score of 9.8 indicates a critical severity flaw. The description states that a remote attacker can execute arbitrary PHP code on the server, which is a high‑severity flaw. The likely attack vector, inferred from the description, is a remote HTTP request that triggers the vulnerable code paths. No publicly disclosed exploits are referenced, but the nature of the flaw directly allows attackers to run arbitrary PHP code, presenting a significant risk that requires prompt remediation.
OpenCVE Enrichment