OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malicious PHP files disguised as resume attachments. Attackers can upload PHP payloads through the careers job application endpoint and execute system commands via POST requests to the uploaded file in the upload directory.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 10 May 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malicious PHP files disguised as resume attachments. Attackers can upload PHP payloads through the careers job application endpoint and execute system commands via POST requests to the uploaded file in the upload directory. | |
| Title | OpenCATS 0.9.4 Remote Code Execution via Resume Upload | |
| First Time appeared |
Opencats
Opencats opencats |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:opencats:opencats:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Opencats
Opencats opencats |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-10T12:43:54.993Z
Reserved: 2026-02-01T11:24:18.717Z
Link: CVE-2021-47936
No data.
Status : Received
Published: 2026-05-10T13:16:29.830
Modified: 2026-05-10T13:16:29.830
Link: CVE-2021-47936
No data.
OpenCVE Enrichment
Updated: 2026-05-10T15:30:14Z
Weaknesses