Impact
The vulnerability exists in the MacCMS10 Template Handler endpoint, specifically in the handling of the path /admin1.php/admin/template/index/path/.%40template%40default%40html%40label.html. The flaw allows an attacker to supply a crafted path that is not properly sanitized, resulting in an operating‑system command being executed. The CVE description confirms remote initiation of the attack and indicates that the exploit has been publicized, implying that an attacker could potentially execute arbitrary commands on the affected server.
Affected Systems
Infections are limited to installations of magicblack MacCMS10 version 2026.1000.4055 that expose the /admin1.php/admin/template/index/path/ endpoint. Any site running this component and allowing public access to the endpoint is potentially vulnerable, while installations without this endpoint or those that restrict access remain unaffected.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium severity. The EPSS score of 1.57% signals that exploitation is unlikely yet not impossible, and the vulnerability is not listed in the CISA KEV catalog. An attacker can send a crafted request to the vulnerable endpoint, triggering an OS command injection. Public exploit code has been released, so exposed systems face a significant risk if the flaw is not mitigated.
OpenCVE Enrichment