PT-2019-10216 · Frog Cms · Frog Cms

Hlhai

·

Published

2019-02-11

·

Updated

2019-02-11

·

CVE-2018-20773

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Frog CMS version 0.9.5
Description: The issue allows PHP code execution. This can be achieved by visiting the "admin/?/page/edit/1" endpoint and inserting additional <?php lines.
Recommendations: For Frog CMS version 0.9.5, consider restricting access to the "admin/?/page/edit/1" endpoint until a patch is available. As a temporary workaround, avoid using the endpoint for editing pages to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-20773

Affected Products

Frog Cms