PT-2025-52516 · Brainycp · Brainycp

CVE-2023-53945

·

Published

2025-12-19

·

Updated

2025-12-31

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BrainyCP version 1.0
Description BrainyCP version 1.0 has an authenticated remote code execution issue. Logged-in users can inject arbitrary commands through the crontab configuration interface. Attackers can exploit the issue by adding a malicious command to the crontab endpoint, potentially spawning a reverse shell to a specified IP and port. The crontab endpoint is the point of exploitation, and the command parameter is used to inject malicious code.
Recommendations Apply a fix or update to a newer version that addresses this issue. As a temporary workaround, restrict access to the crontab configuration interface to minimize the risk of exploitation.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-53945

Affected Products

Brainycp