RULE(RULE ID:338259)

Rule General Information
Release Date: 2024-07-16
Rule Name: YzmCMS pay_callback Remote Command Execution Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: YzmCMS is a lightweight open-source content management system developed based on YZMPHP. YzmCMS is simple, secure, open-source, and free, and can run on various platforms such as Linux, Windows, MacOSX, Solaris, etc. It focuses on providing solutions for companies, enterprises, and individual webmasters to quickly build websites. Its pay_callback has a remote code execution vulnerability, which can be exploited by attackers to execute arbitrary code on the target server or system without authorization. This could lead to data leakage, system damage, service interruption, or even complete takeover of system control.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.