Description
baigoStudio baigoSSO v3.0.1 allows remote attackers to execute arbitrary PHP code via the first form field of a configuration screen, because this code is written to the BG_SITE_NAME field in the opt_base.inc.php file.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-2079 | baigoStudio baigoSSO v3.0.1 allows remote attackers to execute arbitrary PHP code via the first form field of a configuration screen, because this code is written to the BG_SITE_NAME field in the opt_base.inc.php file. |
References
| Link | Providers |
|---|---|
| https://github.com/baigoStudio/baigoSSO/issues/12 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T22:10:08.408Z
Reserved: 2019-03-24T00:00:00.000Z
Link: CVE-2019-10015
No data.
Status : Modified
Published: 2019-03-24T22:29:00.297
Modified: 2024-11-21T04:18:13.487
Link: CVE-2019-10015
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD