Description
A vulnerability has been found in RooCMS up to 1.2.2/1.3.4/1.4RC2. This impacts the function eval of the file roocms/site_pagePHP.php of the component Frontend Rendering. Such manipulation of the argument content leads to code injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-21
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Assess Impact
AI Analysis

Impact

The vulnerability exists in RooCMS versions up to 1.2.2, 1.3.4, and 1.4RC2 and allows an attacker to manipulate the argument passed to the eval function in roocms/site_pagePHP.php, leading to code injection. This flaw is a direct code execution vector that permits remote attackers to run arbitrary PHP code on the web server, compromising confidentiality, integrity, and availability. The weakness corresponds to inputs that are evaluated by the PCRE engine (CWE-94) and improper validation of the argument (CWE-74).

Affected Systems

Affected systems are installations of RooCMS, specifically the Frontend Rendering component that includes site_pagePHP.php. The vulnerability applies to RooCMS releases up to version 1.2.2, 1.3.4, and 1.4RC2, with no newer versions documented as protected in the supplied data.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation but the public disclosure means it could be used by adversaries. The attack vector is remote, requiring only web traffic to the vulnerable component. The scope extends to the server itself, potentially allowing full control over the affected system.

Generated by OpenCVE AI on September 21, 2026 at 02:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a patched version of RooCMS or a release beyond 1.4RC2 if available.
  • Restrict remote access to roocms/site_pagePHP.php through firewall or web‑server ACLs so that only trusted hosts can trigger the eval logic.
  • If an upgrade is not feasible, modify the code to remove the eval call or sanitize/encode the argument passed to it to prevent executable code.
  • Continuously monitor web server logs for anomalous PHP execution attempts or suspicious requests targeting site_pagePHP.php.

Generated by OpenCVE AI on September 21, 2026 at 02:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in RooCMS up to 1.2.2/1.3.4/1.4RC2. This impacts the function eval of the file roocms/site_pagePHP.php of the component Frontend Rendering. Such manipulation of the argument content leads to code injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title RooCMS Frontend Rendering site_pagePHP.php eval code injection
First Time appeared Roocms
Roocms roocms
Weaknesses CWE-74
CWE-94
CPEs cpe:2.3:a:roocms:roocms:*:*:*:*:*:*:*:*
Vendors & Products Roocms
Roocms roocms
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-21T15:59:44.854Z

Reserved: 2026-09-20T10:28:47.977Z

Link: CVE-2026-94103

cve-icon Vulnrichment

Updated: 2026-09-21T15:59:37.313Z

cve-icon NVD

Status : Deferred

Published: 2026-09-21T02:16:53.673

Modified: 2026-09-21T16:17:28.897

Link: CVE-2026-94103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:25:18Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')