PT-2016-7835 · Zikula · Zikula
Xyntax
·
Published
2016-12-05
·
Updated
2016-12-27
·
CVE-2016-9835
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zikula versions 1.3.x through 1.3.10
Zikula versions 1.4.x through 1.4.3
Description
A directory traversal issue in the file "jcss.php" allows a remote attacker to launch a PHP object injection by uploading a serialized file.
Recommendations
For Zikula versions 1.3.x through 1.3.10, update to version 1.3.11 or later.
For Zikula versions 1.4.x through 1.4.3, update to version 1.4.4 or later.
Fix
Command Injection
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zikula