OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malicious PHP files disguised as resume attachments. Attackers can upload PHP payloads through the careers job application endpoint and execute system commands via POST requests to the uploaded file in the upload directory.
Metrics
Affected Vendors & Products
References
History
Sun, 10 May 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malicious PHP files disguised as resume attachments. Attackers can upload PHP payloads through the careers job application endpoint and execute system commands via POST requests to the uploaded file in the upload directory. | |
| Title | OpenCATS 0.9.4 Remote Code Execution via Resume Upload | |
| First Time appeared |
Opencats
Opencats opencats |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:opencats:opencats:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Opencats
Opencats opencats |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-10T12:43:54.993Z
Reserved: 2026-02-01T11:24:18.717Z
Link: CVE-2021-47936
No data.
Status : Received
Published: 2026-05-10T13:16:29.830
Modified: 2026-05-10T13:16:29.830
Link: CVE-2021-47936
No data.
OpenCVE Enrichment
Updated: 2026-05-10T15:30:14Z