← Vulnerability feed

Vulnerability record · CVE-2020-29279 · published 2 December 2020

CVE-2020-29279: 74CMS assign_resume_tpl remote file inclusion leads to code execution

74cms · 74cms

The assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 performs a PHP remote file inclusion, letting an attacker pull in a remote file and execute code. Because the endpoint is reachable without authentication, any exposed 74CMS instance below 6.0.48 is at risk of full compromise.

9.8 CVSS 3.1 Critical EPSS 53% · top 1.1%
9.8CVSS 3.1 base score, v2 7.5
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 allows remote code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a CVSS of 9.8, public exploit references, and a very high EPSS score makes this an urgent patch target.

What it is

The assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 performs a PHP remote file inclusion, letting an attacker pull in a remote file and execute code. Because the endpoint is reachable without authentication, any exposed 74CMS instance below 6.0.48 is at risk of full compromise.

Impact

An unauthenticated attacker can execute arbitrary PHP code on the server, leading to full application and host compromise, data theft, or use of the host as a foothold.

Attack surface

Reached over the network through the assign_resume_tpl method in BaseController; the CVSS vector shows no privileges and no user interaction required, so the request can be sent directly to the vulnerable endpoint.

Exploitation

Not listed in CISA KEV, but EPSS is 0.52881 (98.9th percentile) and both references are tagged Exploit, indicating public exploit material exists and exploitation is likely.

What to do

  • Upgrade 74CMS to 6.0.48 or later, which is the fixed version named in the advisory.
  • If immediate upgrade is not possible, block or restrict access to the assign_resume_tpl endpoint and the BaseController route at the web server or WAF.
  • Disable allow_url_include and allow_url_fopen in PHP where feasible to blunt remote file inclusion.
  • Run the 74CMS application with least privilege and restrict outbound network access so a successful inclusion cannot fetch attacker-hosted payloads.
  • Audit the host for webshells and unexpected PHP files after any suspected exposure.

Detection

  • Search web and PHP logs for requests to assign_resume_tpl or BaseController paths with remote URL parameters.
  • Monitor outbound HTTP requests from the web server to unfamiliar hosts, which may indicate remote payload retrieval.
  • Scan the webroot for newly created or modified PHP files and known webshell patterns.
  • Alert on PHP include or require errors referencing remote URLs in application logs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-29279 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2020-29279), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.