PT-2019-12267 · Soy · Soy Cms

Ryan0Lb

+1

·

Published

2019-04-20

·

Updated

2024-08-04

·

CVE-2019-11376

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SOY CMS version 3.0.2
Description The issue allows remote attackers to execute arbitrary PHP code via a <?php substring in the second text box. It is based on an assumption that the content is made editable on its own.
Recommendations For SOY CMS version 3.0.2, consider removing or restricting the ability to input PHP code in the second text box as a temporary workaround until a patch is available.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2019-11376

Affected Products

Soy Cms