PT-2005-2833 · Cutenews · Cutenews

John Cantu

·

Published

2005-06-07

·

Updated

2025-01-16

·

CVE-2005-1876

CVSS v3.1

4.5

Medium

VectorAV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions CuteNews versions 1.3.6 and earlier
Description A direct code injection issue allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.
Recommendations For CuteNews versions 1.3.6 and earlier, consider restricting access to administrative privileges and limiting the ability to inject code into template files until a fix is available. As a temporary workaround, consider disabling the template editing feature for users with administrative privileges to minimize the risk of exploitation.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2005-1876

Affected Products

Cutenews