PT-2026-33782 · Unknown · Pagekit Cms
S4Nnty
·
Published
2026-04-20
·
Updated
2026-04-21
·
CVE-2026-6652
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:L/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Pagekit CMS versions prior to 1.0.19
Description
An issue exists in the StringStorage Template Handler component within the
evaluate() function of the file 'app/modules/view/src/PhpEngine.php'. This flaw leads to improper neutralization of directives in dynamically evaluated code, which allows for remote code execution.Recommendations
Update to a version later than 1.0.18.
As a temporary workaround, restrict access to the
evaluate() function in 'app/modules/view/src/PhpEngine.php' to minimize the risk of exploitation.Exploit
Fix
RCE
Code Injection
Eval Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pagekit Cms