PT-2026-28749 · Code Projects · Chamber Of Commerce Membership Management System
Y7_0X
·
Publicado
2026-03-29
·
Atualizado
2026-03-29
·
CVE-2026-5041
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:L/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
code-projects Chamber of Commerce Membership Management System version 1.0
Description
A flaw exists in the Chamber of Commerce Membership Management System that allows for command injection. This issue is located in the
fwrite function within the admin/pageMail.php file. The mailSubject and mailMessage arguments can be manipulated to execute arbitrary commands. The attack can be initiated remotely, and an exploit is publicly available.Recommendations
Versions prior to 1.0 are affected.
As a temporary workaround, consider restricting access to the
admin/pageMail.php file until a fix is available.
Avoid using the mailSubject and mailMessage parameters in the affected file until the issue is resolved.Exploit
Correção
Command Injection
Special Elements Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Chamber Of Commerce Membership Management System