PT-2017-13677 · Genix · Genixcms

Publicado

2017-09-27

·

Atualizado

2022-05-13

·

CVE-2017-14763

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GeniXCMS version 1.1.4
Description The issue allows remote authenticated users to execute arbitrary PHP code via a .php file in a ZIP archive of a theme on the Install Themes page.
Recommendations For GeniXCMS version 1.1.4, consider disabling the theme installation feature until a patch is available to prevent the execution of arbitrary PHP code. Restrict access to the Install Themes page to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2017-14763
GHSA-2F6R-892P-69G5

Produtos afetados

Genixcms