VDB
Sign up
HIGH8.8

GHSA-5cmg-8m8p-whmj

GeniXCMS arbitrary PHP code execution

Details

In the Upload Modules page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a module.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/genix/cms

No fixed version published yet for genix/cms (composer). Pin to a known-safe version or switch to an alternative.

References