VDB
Sign up
HIGH7.8

GHSA-h92m-4g9m-72vr

juzawebCMS Injection vulnerability

Details

An issue in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted file to the custom plugin function.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/juzaweb/cms
Introduced in: 0

No fixed version published yet for juzaweb/cms (composer). Pin to a known-safe version or switch to an alternative.

References