Description
An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/stylesheet.php by using a .php extension in the New Stylesheet Name field in conjunction with <?php content, because of insufficient input validation in apps/designer/handlers/csspreview.php.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5689 | An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/stylesheet.php by using a .php extension in the New Stylesheet Name field in conjunction with <?php content, because of insufficient input validation in apps/designer/handlers/csspreview.php. |
Github GHSA |
GHSA-x2w2-qgv6-8xrm | Elefant CMS PHP Code Execution Vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T10:39:58.969Z
Reserved: 2018-09-12T00:00:00.000Z
Link: CVE-2018-16975
No data.
Status : Modified
Published: 2018-09-12T21:29:00.863
Modified: 2024-11-21T03:53:37.667
Link: CVE-2018-16975
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA