Impact
The vulnerability exists in RooCMS versions up to 1.2.2, 1.3.4, and 1.4RC2 and allows an attacker to manipulate the argument passed to the eval function in roocms/site_pagePHP.php, leading to code injection. This flaw is a direct code execution vector that permits remote attackers to run arbitrary PHP code on the web server, compromising confidentiality, integrity, and availability. The weakness corresponds to inputs that are evaluated by the PCRE engine (CWE-94) and improper validation of the argument (CWE-74).
Affected Systems
Affected systems are installations of RooCMS, specifically the Frontend Rendering component that includes site_pagePHP.php. The vulnerability applies to RooCMS releases up to version 1.2.2, 1.3.4, and 1.4RC2, with no newer versions documented as protected in the supplied data.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation but the public disclosure means it could be used by adversaries. The attack vector is remote, requiring only web traffic to the vulnerable component. The scope extends to the server itself, potentially allowing full control over the affected system.
OpenCVE Enrichment