VDB
Sign up
CRITICAL9.8

GHSA-77j2-7whr-6vpx

Elefant CMS Code Execution Vulnerability

Quick fix

GHSA-77j2-7whr-6vpx — elefant/cms: upgrade to the fixed version with the command below.

composer require elefant/cms:^2.0.7

Details

An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in `apps/filemanager/upload/drop.php` by using `/filemanager/api/rm/.htaccess` to remove the .htaccess file, and then using a filename that ends in .php followed by space characters (for bypassing the blacklist).

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/elefant/cms
Introduced in: 0Fixed in: 2.0.7
Fixcomposer require elefant/cms:^2.0.7

References