9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() function at config.php. This vulnerability is exploitable via a crafted input.
AI Analysis
Remote code execution vulnerability in Slah CMS via crafted input to session() function at config.php
Basic Information
ID
CVE-2026-30993
Source
mitre
Published
Apr 15, 2026 at 00:00
Modified
Apr 16, 2026 at 14:06
Affected Product
Vendor
Slah Informatica
Product
Slah CMS
Version
v1.5.0 and below
Affected Versions
n/a n/a n/a
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
Slah Informatica
Product
Slah CMS
Version
v1.5.0 and below