
🚨 High - Aero CMS PHP Code Injection (CVE-2022-50944) Aero CMS 0.0.1 contains a PHP code injection vulnerability that allows authenticated attackers to execute arbitrary code. By uploading malicious PHP files via the image parameter in the posts.php endpoint, an attacker can trigger execution on the server, leading to full system compromise. 👉 Affected: Aero CMS 0.0.1
Post summary
Aero CMS 0.0.1 suffers from a PHP code injection flaw via the image parameter that allows authenticated users to upload malicious PHP files, enabling arbitrary code execution and full system compromise.


