Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w7vm-4v3j-vgpw

Опубликовано: 04 авг. 2023
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

PyroCMS remote code execution vulnerability

PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system.

Пакеты

Наименование

pyrocms/pyrocms

composer
Затронутые версииВерсия исправления

<= 3.9

Отсутствует

EPSS

Процентиль: 98%
0.4933
Средний

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system.

EPSS

Процентиль: 98%
0.4933
Средний

9.8 Critical

CVSS3