CRITICAL9.8
GHSA-fwvc-9xhj-26v5
Badaso vulnerable to Remote Code Execution via malicious file upload
Quick fix
GHSA-fwvc-9xhj-26v5 — badaso/core: upgrade to the fixed version with the command below.
composer require badaso/core:^2.6.1Details
Badaso allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate the data uploaded by users.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-41711[ADVISORY]
- https://github.com/uasoft-indonesia/badaso/issues/802[WEB]
- https://github.com/uasoft-indonesia/badaso/commit/22250eca7c364d991ce9e0a723941eae4889d6f9[WEB]
- https://fluidattacks.com/advisories/harlow[WEB]
- https://github.com/uasoft-indonesia/badaso[PACKAGE]