Impact
The vulnerability lies in the project task export endpoint of WookTeam, where a base64‑encoded data parameter is decoded and directly fed into a PHP eval call after wrapping it with string2array. Because eval receives the raw content when the decoded string begins with "array", an attacker can embed arbitrary PHP code to be executed with the web server's privileges. This flaw therefore provides a straightforward pathway to remote code execution on any system running the affected software.
Affected Systems
The flaw affects all deployments of WookTeam version 1.6.6 and earlier. The product name is WookTeam and there are no known vendor identifiers listed. Applications using these versions should verify which version they run and determine whether they are exposed to the vulnerable /api/project/task/export interface.
Risk and Exploitability
No EPSS impact score was published and the vulnerability is not listed in CISA’s KEV catalog, but the nature of the flaw—unchecked eval on user input—represents a high‑severity issue that can be triggered by sending a crafted request to the exposed API. Because the description does not mention authentication or network restrictions, it is reasonable to infer that the API is reachable by attackers who can reach the host, making the likelihood of exploitation high for exposed instances. The absence of a CVSS score means the actual numeric severity is unknown, but the remote code execution potential warrants immediate attention.
OpenCVE Enrichment