CVE-2025-50881
The flow/admin/moniteur.php script in Use It Flow administration website before 10.0.0 is vulnerable to Remote Code Execution. When handling GET requests,...
- تم النشر
- 16/03/2026
- محدث
- 05/07/2026
- تخصيص CNA
- mitre
- الأدلة المرصودة
- 08/08/2026
CVSS الأساسي
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:Hمنخفض · الثلاثين يومًا القادمة
- المئوية
- 47.6%
- تاريخ الموديل
- 21/09/2026
EPSS هو تقدير إحصائي، وليس يقينًا أو مقياسًا للتأثير. ادمجها مع CVSS وحالة KEV والتعرض وبيئتك.
ملخص
The `flow/admin/moniteur.php` script in Use It Flow administration website before 10.0.0 is vulnerable to Remote Code Execution. When handling GET requests, the script takes user-supplied input from the `action` URL parameter, performs insufficient validation, and incorporates this input into a string that is subsequently executed by the `eval()` function. Although a `method_exists()` check is performed, it only validates the part of the user input *before* the first parenthesis `(`, allowing an attacker to append arbitrary PHP code after a valid method call structure. Successful exploitation allows an unauthenticated or trivially authenticated attacker to execute arbitrary PHP code on the server with the privileges of the web server process. السكربت `flow/admin/moniteur.php` في موقع إدارة Use It Flow قبل الإصدار 10.0.0 معرض لتنفيذ التعليمات البرمجية عن بُعد. عند معالجة طلبات GET، يأخذ السكربت مدخلات يقدمها المستخدم من معامل URL `action`، ويجري تحققًا غير كافٍ، ويدمج هذه المدخلات في سلسلة نصية يتم تنفيذها لاحقًا بواسطة دالة `eval()`. على الرغم من إجراء فحص `method_exists()`، فإنه يتحقق فقط من جزء الإدخال *قبل* القوس الأول `(`، مما يسمح للمهاجم بإلحاق كود PHP تعسفي بعد بنية استدعاء أسلوب صالحة. يتيح الاستغلال الناجح لمهاجم غير مصادق أو مصادق بشكل تافه تنفيذ كود PHP تعسفي على الخادم بصلاحيات عملية خادم الويب.
المصادر
1API SAS استخدام التدفق RCE
الاستخدام المسؤول
استخدم معلومات الثغرات الأمنية فقط على الأنظمة التي تمتلكها أو المرخص لها باختبارها. يرتبط Kitploit ببيانات تعريف البحث العامة ولا يخزن أكواد الاستغلال أو الحمولات الضارة.