Vulnerability record · CVE-2020-29279 · published 2 December 2020
CVE-2020-29279: 74CMS assign_resume_tpl remote file inclusion leads to code execution
74cms · 74cms
The assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 performs a PHP remote file inclusion, letting an attacker pull in a remote file and execute code. Because the endpoint is reachable without authentication, any exposed 74CMS instance below 6.0.48 is at risk of full compromise.
Description
PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 allows remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution with a CVSS of 9.8, public exploit references, and a very high EPSS score makes this an urgent patch target.
What it is
The assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 performs a PHP remote file inclusion, letting an attacker pull in a remote file and execute code. Because the endpoint is reachable without authentication, any exposed 74CMS instance below 6.0.48 is at risk of full compromise.
Impact
An unauthenticated attacker can execute arbitrary PHP code on the server, leading to full application and host compromise, data theft, or use of the host as a foothold.
Attack surface
Reached over the network through the assign_resume_tpl method in BaseController; the CVSS vector shows no privileges and no user interaction required, so the request can be sent directly to the vulnerable endpoint.
Exploitation
Not listed in CISA KEV, but EPSS is 0.52881 (98.9th percentile) and both references are tagged Exploit, indicating public exploit material exists and exploitation is likely.
What to do
- Upgrade 74CMS to 6.0.48 or later, which is the fixed version named in the advisory.
- If immediate upgrade is not possible, block or restrict access to the assign_resume_tpl endpoint and the BaseController route at the web server or WAF.
- Disable allow_url_include and allow_url_fopen in PHP where feasible to blunt remote file inclusion.
- Run the 74CMS application with least privilege and restrict outbound network access so a successful inclusion cannot fetch attacker-hosted payloads.
- Audit the host for webshells and unexpected PHP files after any suspected exposure.
Detection
- Search web and PHP logs for requests to assign_resume_tpl or BaseController paths with remote URL parameters.
- Monitor outbound HTTP requests from the web server to unfamiliar hosts, which may indicate remote payload retrieval.
- Scan the webroot for newly created or modified PHP files and known webshell patterns.
- Alert on PHP include or require errors referencing remote URLs in application logs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.74cms.com/news/show-2497.html | ExploitVendor Advisory |
| https://github.com/BigTiger2020/74CMS/blob/main/README.md | ExploitThird Party Advisory |
| http://www.74cms.com/news/show-2497.html | ExploitVendor Advisory |
| https://github.com/BigTiger2020/74CMS/blob/main/README.md | ExploitThird Party Advisory |
Track CVE-2020-29279 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-29279), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.