Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x2w2-qgv6-8xrm

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Elefant CMS PHP Code Execution Vulnerability

An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/stylesheet.php by using a .php extension in the New Stylesheet Name field in conjunction with <?php content, because of insufficient input validation in apps/designer/handlers/csspreview.php.

Пакеты

Наименование

elefant/cms

composer
Затронутые версииВерсия исправления

< 2.0.7

2.0.7

EPSS

Процентиль: 69%
0.00604
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.8
nvd
больше 7 лет назад

An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/stylesheet.php by using a .php extension in the New Stylesheet Name field in conjunction with <?php content, because of insufficient input validation in apps/designer/handlers/csspreview.php.

EPSS

Процентиль: 69%
0.00604
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94