Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-77939

Опубликовано: 28 авг. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attackers with a valid API token to read arbitrary files by passing unsanitized user-supplied input to the Symfony ExpressionLanguage engine via the POST /api/v1/query endpoint. Attackers can leverage exposed application objects including filesystem() and serializers() within the evaluation scope to read arbitrary server files and achieve conditional remote code execution if a PHP file can be placed on disk through a secondary vector.

EPSS

Процентиль: 38%
0.00444
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 6.5
github
23 дня назад

Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attackers with a valid API token to read arbitrary files by passing unsanitized user-supplied input to the Symfony ExpressionLanguage engine via the POST /api/v1/query endpoint. Attackers can leverage exposed application objects including filesystem() and serializers() within the evaluation scope to read arbitrary server files and achieve conditional remote code execution if a PHP file can be placed on disk through a secondary vector.

EPSS

Процентиль: 38%
0.00444
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-94