CVE-2018-20300: Code Injection
Published Dec 20, 2018
·Updated
Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is injected into a memberform.$fid.php file.
Affected Software
1 affected component
Phome Empirecms=7.5
Event History
Dec 20, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20300?
CVE-2018-20300 is classified as a critical vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2018-20300?
To mitigate CVE-2018-20300, upgrade Empire CMS to a version that is not vulnerable, preferably above 7.5.
3
What impact does CVE-2018-20300 have on my system?
CVE-2018-20300 can lead to unauthorized remote code execution, potentially compromising the entire system.
4
Is CVE-2018-20300 easily exploitable?
Yes, CVE-2018-20300 can be exploited easily by remote attackers using crafted requests.
5
What versions of Empire CMS are affected by CVE-2018-20300?
Empire CMS version 7.5 is the only affected version regarding CVE-2018-20300.