PurpleOps[verified]@PurpleOps_ioPatch
CVE-2019-25687 is a critical remote code execution flaw in Pegasus CMS 1.0 that allows unauthenticated attackers to execute arbitrary PHP code via the extra_fields.php plugin; the vendor has released a fix, and the advisory recommends patching or disabling the vulnerable functionality.
cybersecuritypath@cybrsecpathDisclosure
The tweet announces the disclosure of a remote code execution flaw (CVE-2019-25687) in Pegasus CMS 1.0, referencing an article link, but provides no PoC, exploit details, active exploitation evidence, or patch information.
CTIWatch@ctiwatchcloudGeneral
The post lists three CVEs with their CVSS scores and a link to a vulnerability page without providing any detailed technical, exploit, or mitigation information.
CVEFind.com@CveFindComDisclosure
The tweet discloses CVE‑2019‑25687 as a critical remote code execution flaw in Pegasus CMS 1.0’s extra_fields.php plugin, detailing unsafe eval usage but providing no PoC, exploitation tool, patch, or active exploitation report.
CVE@CVEnewDisclosure
CVE-2019-25687 is a remote code execution vulnerability in Pegasus CMS 1.0's extra_fields.php plugin that allows unauthenticated attackers to run arbitrary commands.
0day Signal@0dayPublishingDisclosure
Pegasus CMS 1.0 has an unauthenticated Remote Code Execution vulnerability through eval() in the action parameter of submit.php, rated at CVSS 9.3.