Description


A vulnerability was found in Elefant CMS 1.3.12-RC. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /designer/add/layout. The manipulation leads to code injection. The attack can be launched remotely. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component.

Related CPE's


References


http://seclists.org/fulldisclosure/2017/Feb/39

ExploitMailing ListThird Party Advisory

https://vuldb.com/?id.97261

Third Party Advisory

Weaknesses



CWE-94


CWE-94

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.8 · High

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2022-06-20T05:15:07.937

3 years ago

Last modified

2022-06-27T18:12:35.797

3 years ago