CVE-2017-14048: Blackcat-CMS Blackcat CMS
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
BlackCat CMS 1.2 allows remote authenticated users to inject arbitrary PHP code into info.php via a crafted new_modulename parameter to backend/addons/ajax_create.php. NOTE: this can be exploited via CSRF.
Affected products
- Blackcat-CMS Blackcat CMS: version 1.2 only
Published 2017-08-31. Last modified 2026-06-17.