BrainyCP 1.0 contains an authenticated remote code...
High severity
Unreviewed
Published
Dec 19, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Dec 19, 2025
Published to the GitHub Advisory Database
Dec 19, 2025
BrainyCP 1.0 contains an authenticated remote code execution vulnerability that allows logged-in users to inject arbitrary commands through the crontab configuration interface. Attackers can exploit the crontab endpoint by adding a malicious command that spawns a reverse shell to a specified IP and port.
References