PT-2018-14207 · Hisi · Hisiphp

Published

2018-10-01

·

Updated

2019-01-08

·

CVE-2018-17827

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HisiPHP version 1.0.8
Description The issue allows remote attackers to execute arbitrary PHP code. This is achieved by editing a plugin's name to contain the malicious code, which is then injected into the app/admin/model/AdminPlugins.php file.
Recommendations For HisiPHP version 1.0.8, consider restricting access to the plugin editing functionality until a patch is available. As a temporary workaround, avoid using the plugin name field to inject malicious PHP code.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-17827

Affected Products

Hisiphp