CVE-2009-20010Exploit

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Dogfood CRM version 2.0.10 contains a remote command execution vulnerability in the spell.php script used by its mail subsystem. The vulnerability arises from unsanitized user input passed via a POST request to the data parameter, which is processed by the underlying shell without adequate escaping. This allows attackers to inject arbitrary shell commands and execute them on the server. The flaw is exploitable without authentication and was discovered by researcher LSO.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC and exploit tooling are both present
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-07: 1PoC Mentioned / Linked · 2026-04-07: 1Exploit Tool / Code · 2026-04-07: 1Technical Details · 2026-04-07: 104-07
Signal classification1 categories
Exploit
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2009-20010: Do... Unauthenticated RCE via POST to spell.php - classic shell injection goldmine with Metasploit module ready to deploy #RCE #DogfoodCRM #ShellInjection. https://zerodaysignal.com/vulnerability/CVE-2009-20010 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2009‑20010 as an unauthenticated remote code execution vulnerability in spell.php, highlights a ready Metasploit module, and links to a vulnerability listing—no patch or active exploitation claimed.

    0000027
    204 followersView on X

Explore more