PT-2025-38760 · Creacast · Creabox Manager

Published

2025-09-22

·

Updated

2025-10-17

·

CVE-2025-57439

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Creacast Creabox Manager version 4.4.4
Description A critical Remote Code Execution issue exists in Creacast Creabox Manager version 4.4.4. An authenticated attacker can inject arbitrary Lua code into the configuration through the edit.php endpoint. This injected code is then executed on the server, potentially leading to full system compromise, including the ability to execute arbitrary commands or establish a reverse shell. The vulnerable API endpoint is /edit.php. The vulnerable parameter is the configuration data submitted to the edit.php endpoint.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-57439

Affected Products

Creabox Manager