CVE-2017-14048: Blackcat-CMS Blackcat CMS

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

BlackCat CMS 1.2 allows remote authenticated users to inject arbitrary PHP code into info.php via a crafted new_modulename parameter to backend/addons/ajax_create.php. NOTE: this can be exploited via CSRF.

Affected products

Published 2017-08-31. Last modified 2026-06-17.