CVE-2025-50881 is a remote code execution vulnerability in the flow/admin/moniteur.php script of the Use It Flow administration website before version 10.0.0. The flaw arises when the application processes GET requests and reads attacker-controlled data from the action URL parameter. That value is insufficiently validated and is then incorporated into a string that is executed via PHP eval(). Although the code performs a method_exists() check, the validation only applies to the portion of the supplied input before the first ( character. This allows an attacker to supply input that begins with a valid method call pattern and then append arbitrary PHP code after it, bypassing the intended safeguard and reaching eval() with attacker-controlled code.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H indicates high impact to confidentiality, integrity, and availability.If you can’t patch tonight, do this now.
flow/admin/moniteur.php. Deploy WAF or reverse-proxy rules to deny suspicious requests containing crafted action parameters, especially those including parentheses or PHP code fragments. Monitor web server and application logs for anomalous requests to the vulnerable endpoint and for signs of post-exploitation such as unexpected file creation or command execution. These measures reduce exposure but do not eliminate the underlying flaw.Patch, then assume compromise.
flow/admin/moniteur.php should be corrected by removing the use of eval() on user-influenced input and replacing it with a safe dispatch mechanism based on a strict allowlist of permitted actions or method names. Validation should apply to the entire action value, not only the substring before the first parenthesis.No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.