PT-2026-35940 · Eyoucms · Eyoucms

Anch0R

·

Published

2026-04-29

·

Updated

2026-04-29

·

CVE-2026-7388

CVSS v2.0

5.8

Medium

VectorAV:N/AC:L/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions EyouCMS versions prior to 1.8.0
Description A weakness in the Template File Handler component allows for remote code injection. The issue exists within the editFile() function located in the application/admin/logic/FilemanagerLogic.php file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the editFile() function in the application/admin/logic/FilemanagerLogic.php file.

Exploit

Special Elements Injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7388

Affected Products

Eyoucms