CVE-2026-7388 PUBLISHED

EyouCMS Template File FilemanagerLogic.php editFile code injection

Assigner: VulDB
Reserved: 29.04.2026 Published: 29.04.2026 Updated: 29.04.2026

A weakness has been identified in EyouCMS up to 1.7.9. Impacted is the function editFile of the file application/admin/logic/FilemanagerLogic.php of the component Template File Handler. Executing a manipulation can lead to code injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.1

Product Status

Vendor n/a
Product EyouCMS
Versions
  • Version 1.7.0 is affected
  • Version 1.7.1 is affected
  • Version 1.7.2 is affected
  • Version 1.7.3 is affected
  • Version 1.7.4 is affected
  • Version 1.7.5 is affected
  • Version 1.7.6 is affected
  • Version 1.7.7 is affected
  • Version 1.7.8 is affected
  • Version 1.7.9 is affected

Credits

  • anch0r (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Code Injection CWE
  • Injection CWE