Impact
A vulnerability in Apioo Fusio allows authenticated users who hold the Developer role to bypass the PHP sandbox allow‑list and execute arbitrary OS commands. The sandbox incorrectly permits functions that transitively invoke system(), enabling a developer‑privileged user to escape the sandbox and run commands on the server. This flaw results in full server compromise. The weakness is classified as CWE‑78, indicating exploitation of operating‑system command injection.
Affected Systems
Apioo Fusio version 8.8.3 is affected. No other version information is provided in the CNA data, so only this specific release should be considered vulnerable until further notice.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability with potential for complete compromise. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, so there is no evidence of widespread exploitation yet. Attackers must first authenticate and possess a Developer‑role account, which suggests the likely attack vector is an internal user or a compromised account. Exploitation requires only exploitation of the allow‑list bypass and does not rely on any complex prerequisites beyond the user’s role.
OpenCVE Enrichment