CRITICAL9.9
GHSA-xcq3-7pf3-5jvc
Cockpit PHP Remote File Inclusion vulnerability
Quick fix
GHSA-xcq3-7pf3-5jvc — cockpit-hq/cockpit: upgrade to the fixed version with the command below.
composer require cockpit-hq/cockpit:^2.6.3Details
PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3. Users may upload php files through the system file upload utility to obtain remote code execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/cockpit-hq/cockpit
Introduced in:
0Fixed in: 2.6.3Fix
composer require cockpit-hq/cockpit:^2.6.3