CVE advisoryCRITICAL
CVE-2019-25687
Pegasus CMS 1.0 Remote Code Execution via Extra Fields Plugin
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
Pegasus CMS 1.0 has a critical remote code execution flaw in its extra_fields.php plugin. Unauthenticated attackers can send POST requests with malicious code to a specific endpoint to run arbitrary commands on the server. This could allow attackers to gain control of the system. It is important to determine if this so