First published: Fri Dec 27 2019(Updated: )
ReviewBoard 1.6.17 allows code execution by attaching PHP scripts to review request
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ReviewBoard ReviewBoard | =1.6.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4796 has a high severity rating due to the potential for remote code execution.
To fix CVE-2013-4796, upgrade ReviewBoard to a version that is not affected, such as one later than 1.6.17.
CVE-2013-4796 specifically affects ReviewBoard version 1.6.17.
Yes, due to the potential for code execution, CVE-2013-4796 can lead to unauthorized access and data leakage.
Yes, CVE-2013-4796 can be exploited in a default configuration of ReviewBoard if vulnerable PHP scripts are attached to review requests.