VDB
Sign up
CRITICAL9.8

GHSA-jj62-mc3m-j769

FeehiCMS has an arbitrary file upload vulnerability

Quick fix

GHSA-jj62-mc3m-j769 — feehi/cms: upgrade to the fixed version with the command below.

composer require feehi/cms:^2.0.8.1

Details

There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8.1 at the head image upload, that allows attackers to execute relevant PHP code.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/feehi/cms
Introduced in: 0Fixed in: 2.0.8.1
Fixcomposer require feehi/cms:^2.0.8.1

References