Description
A vulnerability was found in Elefant CMS 1.3.12-RC. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /designer/add/layout. The manipulation leads to code injection. The attack can be launched remotely. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component.
References
http://seclists.org/fulldisclosure/2017/Feb/39
ExploitMailing ListThird Party Advisory
Third Party Advisory
http://seclists.org/fulldisclosure/2017/Feb/39
ExploitMailing ListThird Party Advisory
Third Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
6.3 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2022-06-20T03:15:07.937Z
3 years agoLast modified
2024-11-21T02:22:33.310Z
1 year ago