Описание
Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below contain a Remote Code Execution vulnerability in the CMS Developer menu's Module Templating functionality, allowing authenticated users with "System -> Add/Edit custom modules and templates" permissions to manipulate Twig filters and execute arbitrary server-side functions as the web server user. This issue is fixed in version 4.3.1. To workaround this issue, use the 4.1 and 4.2 patch commits.
Ссылки
- Patch
- Patch
- Release Notes
- Third Party Advisory
- Product
Уязвимые конфигурации
Конфигурация 1Версия от 4.1.0 (включая) до 4.3.1 (исключая)
cpe:2.3:a:xibosignage:xibo:*:*:*:*:*:*:*:*
EPSS
Процентиль: 62%
0.00426
Низкий
7.2 High
CVSS3
Дефекты
CWE-94
EPSS
Процентиль: 62%
0.00426
Низкий
7.2 High
CVSS3
Дефекты
CWE-94