PT-2020-18300 · Fat Free Framework · Fat-Free Framework

Ikkez

·

Published

2020-03-11

·

Updated

2022-05-24

·

CVE-2020-5203

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fat-Free Framework version 3.7.1
Description The issue allows attackers to achieve arbitrary code execution if developers pass user-controlled input, such as $ REQUEST, $ GET, or $ POST, to the framework's Clear method. This can lead to exploitation when user input is not properly sanitized.
Recommendations For Fat-Free Framework version 3.7.1, avoid passing user-controlled input to the Clear method until a patch is available. As a temporary workaround, consider validating and sanitizing all user input before passing it to the framework's methods to minimize the risk of exploitation.

Fix

Special Elements Injection

Code Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5203
GHSA-HPJ2-4HFJ-G233

Affected Products

Fat-Free Framework