Impact
A flaw in mtrano APENCMS’s Template Engine occurs in the eval function used in cms/weasel.php. The function processes the $_CMS['site'] argument, allowing an attacker to inject arbitrary code. This injection could allow an attacker to execute any code on the server, compromising data integrity, confidentiality, and availability of the entire CMS instance.
Affected Systems
The vulnerability exists in all versions of the mtrano APENCMS product prior to the fix, as the vendor uses a rolling release model and has not published explicit fix versions. All installations that have not applied the latest build from the official repository remain affected.
Risk and Exploitability
The CVSS score of 4.8 classifies the issue as moderate severity, and the EPSS score is currently unavailable. The vulnerability is not listed in the CISA KEV catalog, but the exploit is publicly available, and the remote attack vector allows potential exploitation over the network. Consequently, the risk of compromise is enabled only if the vulnerable code is reachable externally.
OpenCVE Enrichment