PT-2012-2039 · Whmcs · Whmcs
Published
2012-01-14
·
Updated
2024-08-06
·
CVE-2011-5061
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
WHMCS versions 4.0.x through 5.0.x
Description
The issue is related to improper handling of characters in the subject field of a crafted ticket, which can trigger arbitrary code execution in the Smarty templating system. This allows remote attackers to execute arbitrary code.
Recommendations
For WHMCS versions 4.0.x through 5.0.x, consider disabling the
functions.php file or restricting access to it until a patch is available. As a temporary workaround, avoid using the subject field in tickets to minimize the risk of exploitation.Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Whmcs