PT-2021-10249 · Phpmywind · Phpmywind

Liao10086

·

Published

2021-08-20

·

Updated

2022-09-20

·

CVE-2020-18885

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: PHPMyWind version 5.6
Description: The issue allows remote attackers to execute arbitrary code via the "text color" field of the component "/admin/web config.php".
Recommendations: For PHPMyWind version 5.6, consider disabling access to the "/admin/web config.php" component until a patch is available. Restrict input for the "text color" field to prevent command injection.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2020-18885

Affected Products

Phpmywind