VDB
Sign up
CRITICAL9.8

GHSA-c7fv-wv9f-cgjw

php-shellcommand command injection vulnerability

Quick fix

GHSA-c7fv-wv9f-cgjw — mikehaertl/php-shellcommand: upgrade to the fixed version with the command below.

composer require mikehaertl/php-shellcommand:^1.6.1

Details

php-shellcommand versions before 1.6.1 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/mikehaertl/php-shellcommand
Introduced in: 0Fixed in: 1.6.1
Fixcomposer require mikehaertl/php-shellcommand:^1.6.1

References