PT-2022-12704 · Fenom · Fenom

Altm4

·

Published

2022-03-28

·

Updated

2022-04-04

·

CVE-2021-46433

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fenom versions 2.12.1 and earlier
Description The issue allows bypassing the sandbox to execute arbitrary PHP code when disable native funcs is true. This is possible through the getTemplateCode() function in fenom/src/Fenom/Template.php.
Recommendations For Fenom versions 2.12.1 and earlier, as a temporary workaround, consider disabling the getTemplateCode() function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-46433
GHSA-674V-3G2W-84GX

Affected Products

Fenom