Dogfood CRM 2.0.10 contains a remote command execution vulnerability in the mail subsystem's spell.php script. The flaw is caused by unsanitized user-supplied input from the POST data parameter being passed to an underlying shell without proper escaping or neutralization of shell metacharacters. As a result, an attacker can inject arbitrary shell commands through crafted POST requests. According to the provided content, the issue is exploitable without authentication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit exploit module targeting Dogfood CRM v2.0.10. The exploit leverages a command injection vulnerability in the spell check feature of the mail component (spell.php). The module is written in Ruby and uses the Metasploit framework's HttpClient mixin to interact with the target. The attacker can specify the URI path to the vulnerable spell.php endpoint (default: /dogfood/mail/spell.php). The exploit works by sending a specially crafted POST request with a payload that is executed on the server, allowing for arbitrary command execution. The module is operational and supports various shell command payloads, with a recommendation for double-reverse telnet due to input restrictions. The code includes a check method to verify if the target is likely vulnerable. The only code file is the exploit module itself, and it is structured according to Metasploit conventions.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.