PT-2017-13678 · Genix · Genixcms

Published

2017-09-27

·

Updated

2022-05-17

·

CVE-2017-14764

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GeniXCMS version 1.1.4
Description The issue allows remote authenticated users to execute arbitrary PHP code via a .php file in a ZIP archive of a module in the Upload Modules page.
Recommendations For GeniXCMS version 1.1.4, consider restricting access to the Upload Modules page until a patch is available, and avoid uploading modules from untrusted sources to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-14764
GHSA-5CMG-8M8P-WHMJ

Affected Products

Genixcms