Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Foam

#26018of 53,624
9.8Total CVSS
Vulnerabilities · 1
PT-2019-13813
9.8
2019-08-07
Kuaifan · Kuaifancms · CVE-2019-14746
**Name of the Vulnerable Software and Affected Versions** KuaiFanCMS version 5.0 **Description** A issue was discovered that allows eval injection by placing PHP code in the `db name` parameter and then making a request to the "config.php" endpoint. **Recommendations** For KuaiFanCMS version 5.0, avoid using the `db name` parameter in the install.php file until a fix is available. As a temporary workaround, consider restricting access to the install.php file and the config.php endpoint to minimize the risk of exploitation.