CRITICAL9.8
GHSA-x2w2-qgv6-8xrm
Elefant CMS PHP Code Execution Vulnerability
Quick fix
GHSA-x2w2-qgv6-8xrm — elefant/cms: upgrade to the fixed version with the command below.
composer require elefant/cms:^2.0.7Details
An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in `/designer/add/stylesheet.php` by using a `.php` extension in the New Stylesheet Name field in conjunction with `<?php` content, because of insufficient input validation in `apps/designer/handlers/csspreview.php`.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-16975[ADVISORY]
- https://github.com/jbroadway/elefant/issues/286[WEB]
- https://github.com/jbroadway/elefant/commit/0795ab57c7ffa53ff4af57e229f6d9680fa54a21[WEB]
- https://github.com/jbroadway/elefant[PACKAGE]
- https://github.com/jbroadway/elefant/releases/tag/elefant_2_0_7_stable[WEB]