VDB
Sign up
HIGH8.8

GHSA-2f6r-892p-69g5

GeniXCMS arbitrary PHP code execution

Details

In the Install Themes page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a theme.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/genix/cms

No fixed version published yet for genix/cms (composer). Pin to a known-safe version or switch to an alternative.

References