OSV 1.4.0 · unreviewed · 修改于 2022-02-18 08:01
发布时间
2022-02-11 08:00
GitHub 审查时间
—
NVD 发布时间
2022-02-10 07:15
源文件
advisories/unreviewed/2022/02/GHSA-5r4j-gp4j-q9p2/GHSA-5r4j-gp4j-q9p2.json
Exponent CMS 2.6.0patch2 allows an authenticated admin user to upload a malicious extension in the format of a ZIP file with a PHP file inside it. After upload it, the PHP file will be placed at "themes/simpletheme/{rce}.php" from where can be accessed in order to execute commands.
该公告没有提供结构化的受影响软件包信息。