CerberusMrXi/CVE-2026-48909-Joomla-SP-Exploit
GitHub: CerberusMrXi/CVE-2026-48909-Joomla-SP-Exploit
针对 Joomla SP LMS 扩展 PHP 对象注入至 RCE 漏洞(CVE-2026-48909)的授权安全测试用利用工具,集成交互式 shell 与路径发现功能。
Stars: 2 | Forks: 0
# CVE-2026-48909-Joomla-SP-Exploit
CVE-2026-48909 - 针对 Joomla SP LMS 扩展版本 <= 4.1.3 的无需身份验证 PHP 对象注入至 RCE exploit。利用 lmsOrders cookie 反序列化,通过 Joomla FormattedtextLogger gadget chain 写入 webshell。包含交互式 shell、路径发现和清理功能。仅供授权的安全测试使用。
标签:Joomla, PHP对象注入, Webshell, 安全测试, 攻击性安全, 逆向工具