HIGH8.8
GHSA-rw82-mhmx-grmj
Guest Entries Remote code execution via file uploads
Quick fix
GHSA-rw82-mhmx-grmj — duncanmcclean/guest-entries: upgrade to the fixed version with the command below.
composer require duncanmcclean/guest-entries:^3.1.2Details
### Impact When using the file uploads feature, it was possible to upload PHP files.
### Patches The vulnerability is fixed in v3.1.2.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/duncanmcclean/guest-entries
Introduced in:
0Fixed in: 3.1.2Fix
composer require duncanmcclean/guest-entries:^3.1.2Packagist/doublethreedigital/guest-entries
Introduced in:
0Fixed in: 3.1.2Fix
composer require doublethreedigital/guest-entries:^3.1.2References
- https://github.com/duncanmcclean/guest-entries/security/advisories/GHSA-rw82-mhmx-grmj[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-47621[ADVISORY]
- https://github.com/duncanmcclean/guest-entries/commit/a8e17b4413bfbbc337a887761a6c858ef1ddb4da[WEB]
- https://github.com/duncanmcclean/guest-entries[PACKAGE]