CVE-2019-25687Disclosure(wisdom / pegasus_cms)

LOWCVSS 9.3 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch wisdom pegasus_cms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticated attackers to execute arbitrary commands by exploiting unsafe eval functionality. Attackers can send POST requests to the submit.php endpoint with malicious PHP code in the action parameter to achieve code execution and obtain an interactive shell.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pegasus_cms

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-05); latest day: 3
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
pegasus_cms

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 2d
01223Mentions · 2026-04-05: 3Mentions · 2026-04-06: 3Patch / Workaround · 2026-04-06: 1Technical Details · 2026-04-05: 3Technical Details · 2026-04-06: 204-0504-06
Signal classification3 categories
Disclosure
466.7%
General
116.7%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-053
Disclosure3
2026-04-063
Disclosure1General1Patch1
Full discourse6 posts
  • cybersecuritypath@cybrsecpath
    Disclosure

    CVE-2019-25687: RCE Flaw in Pegasus CMS 1.0 Now Exposed https://thecybrdef.com/cve-2019-25687-pegasus-cms-rce-flaw/ https://t.co/hoCnWiLY3v

    Post summary

    The tweet announces the disclosure of a remote code execution flaw (CVE-2019-25687) in Pegasus CMS 1.0, referencing an article link, but provides no PoC, exploit details, active exploitation evidence, or patch information.

    0000036
    3 followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2019-25687 | CVSS 9.8 🟠 CVE-2026-5613 | CVSS 8.8 🟠 CVE-2026-5628 | CVSS 8.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post lists three CVEs with their CVSS scores and a link to a vulnerability page without providing any detailed technical, exploit, or mitigation information.

    0000036
    5.6K followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    🚨 Critical CVEs Today: Pegasus CMS stack (CVSS 9.8-9.8) Affected: Pegasus CMS/Pegasus CMS 1.0 Today’s critical CVEs span Pegasus CMS, with an unauthenticated remote code execution path in a plugin. • CVE-2019-25687 (CVSS 9.8) Pegasus CMS 1.0 has a remote code execution flaw in the extra_fields.php plugin that permits unauthenticated attackers to execute arbitrary PHP commands via unsafe eval by sending code in the action parameter to submit.php. 🛠️ Action • Patch Pegasus CMS to the vendor’s latest advisory fix and apply available updates for Pegasus CMS 1.0 • Prioritize internet-facing instances and edge deployments for patching and verification • If a fix is not yet available, disable the affected extra_fields.php functionality or restrict access to submit.php to reduce exposure • Add detections for exploitation patterns: POST requests to submit.php with PHP code in the action parameter and signs of webshell activity • Hunt logs and endpoints for indicators such as process spawning, PHP eval usage, webshell artifacts, and unexpected shell sessions • Validate remediation with version/config checks and monitor environments for reversion or new indicators

    Post summary

    CVE-2019-25687 is a critical remote code execution flaw in Pegasus CMS 1.0 that allows unauthenticated attackers to execute arbitrary PHP code via the extra_fields.php plugin; the vendor has released a fix, and the advisory recommends patching or disabling the vulnerable functionality.

    0000040
    97 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2019-25687: CRITICAL] Pegasus CMS 1.0 has a critical remote code execution vulnerability in extra_fields.php plugin. Exploiting unsafe eval allows attackers to run arbitrary commands remotely.#cve,CVE-2019-25687,#cybersecurity https://cvefind.com/CVE-2019-25687

    Post summary

    The tweet discloses CVE‑2019‑25687 as a critical remote code execution flaw in Pegasus CMS 1.0’s extra_fields.php plugin, detailing unsafe eval usage but providing no PoC, exploitation tool, patch, or active exploitation report.

    0000053
    612 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2019-25687 Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticated attackers to execute arbitrary commands by e… https://www.cve.org/CVERecord?id=CVE-2019-25687

    Post summary

    CVE-2019-25687 is a remote code execution vulnerability in Pegasus CMS 1.0's extra_fields.php plugin that allows unauthenticated attackers to run arbitrary commands.

    00000162
    56.8K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2019-25687: Pegasus CMS 1.0... Unauthenticated RCE via eval() in Pegasus CMS - POST to submit.php with PHP in action param = instant shell, CVSS 9.3 #RCE #eval #shell. https://zerodaysignal.com/vulnerability/CVE-2019-25687 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    Pegasus CMS 1.0 has an unauthenticated Remote Code Execution vulnerability through eval() in the action parameter of submit.php, rated at CVSS 9.3.

    0000085
    187 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwisdompegasus_cms1.0--

Explore more