Impact
The vulnerability exists in Yaojingang GEOFlow’s Superadmin Theme Editor preview functionality, specifically in app/Http/Controllers/Admin/SiteThemeEditorController.php. An attacker can manipulate the 'blade' argument to inject arbitrary code, leading to remote code execution. The flaw is already detected and publicly disclosed, meaning attackers can exploit it over the network without local access.
Affected Systems
Any installation of yaojingang GEOFlow version 2.1.0 or older is affected. The issue resides in the Superadmin Theme Editor component. Version 2.1.1 contains the patch identified by commit 67abfd864a15d169a78429f3290c91cb3b93e849 and resolves the flaw.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate potential impact. EPSS information is not available, and the vulnerability is not listed in CISA’s KEV catalog. The exploit requires remote access to the preview endpoint, and an attacker can trigger code injection by crafting a request that modifies the 'blade' parameter. The lack of a KEV listing does not diminish the risk; the publicly available exploit indicates that exploitation is feasible and potentially widespread.
OpenCVE Enrichment