VDB
Sign up
CRITICAL9.9

GHSA-xcq3-7pf3-5jvc

Cockpit PHP Remote File Inclusion vulnerability

Quick fix

GHSA-xcq3-7pf3-5jvc — cockpit-hq/cockpit: upgrade to the fixed version with the command below.

composer require cockpit-hq/cockpit:^2.6.3

Details

PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3. Users may upload php files through the system file upload utility to obtain remote code execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/cockpit-hq/cockpit
Introduced in: 0Fixed in: 2.6.3
Fixcomposer require cockpit-hq/cockpit:^2.6.3

References