VDB
Sign up
CRITICAL9.8

GHSA-x2w2-qgv6-8xrm

Elefant CMS PHP Code Execution Vulnerability

Quick fix

GHSA-x2w2-qgv6-8xrm — elefant/cms: upgrade to the fixed version with the command below.

composer require elefant/cms:^2.0.7

Details

An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in `/designer/add/stylesheet.php` by using a `.php` extension in the New Stylesheet Name field in conjunction with `<?php` content, because of insufficient input validation in `apps/designer/handlers/csspreview.php`.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/elefant/cms
Introduced in: 0Fixed in: 2.0.7
Fixcomposer require elefant/cms:^2.0.7

References