PT-2020-18300 · Fat Free Framework · Fat-Free Framework
Ikkez
·
Published
2020-03-11
·
Updated
2022-05-24
·
CVE-2020-5203
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Fat-Free Framework version 3.7.1
Description
The issue allows attackers to achieve arbitrary code execution if developers pass user-controlled input, such as
$ REQUEST, $ GET, or $ POST, to the framework's Clear method. This can lead to exploitation when user input is not properly sanitized.Recommendations
For Fat-Free Framework version 3.7.1, avoid passing user-controlled input to the Clear method until a patch is available. As a temporary workaround, consider validating and sanitizing all user input before passing it to the framework's methods to minimize the risk of exploitation.
Fix
Special Elements Injection
Code Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fat-Free Framework