PHP Code Injection Vulnerability in OpenCATS Installer by OpenCATS

⚠️ CVE-Referenzen: CVE-2026-27760
Opencats - Opencats - CRITICAL - CVE-2026-27760. OpenCATS, prior to commit 3002a29, is vulnerable to a PHP code injection issue that affects the installer AJAX endpoint. This vulnerability allows unauthenticated attackers to inject malicious PHP code through the databaseConnectivity action parameter. By exploiting the vulnerability, attackers can break out of the define() string context in config.php using a single quote and a statement separator, enabling them to execute arbitrary code that persists across subsequent page loads as long as the installation wizard remains incomplete. BADGES: 👾 EXPLOITED | 🟡 PoC | SecurityVulnerability.io
Quelle: securityvulnerability.io