First published: Sat Apr 07 2018(Updated: )
In Gxlcms QY v1.0.0713, the update function in Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to execute arbitrary PHP code by placing this code into a template.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gxlcms | =1.0.0713 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-9847.
The title of the vulnerability is 'In Gxlcms QY v1.0.0713 the update function in Lib\Lib\Action\Admin\TplAction.class.php allows remote...'
The description of the vulnerability is 'In Gxlcms QY v1.0.0713, the update function in Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to execute arbitrary PHP code by placing this code into a template.'
The software version affected by this vulnerability is Gxlcms QY v1.0.0713.
The severity of this vulnerability is critical with a CVSS score of 9.8.
Remote attackers can exploit this vulnerability by placing arbitrary PHP code into a template.
No information on a fix for this vulnerability is available.
You can find more information about this vulnerability at http://www.atksec.com/cve/GxlcmsQY-v1.0.0713-update-template-getshell/index.html.
The CWE category of this vulnerability is CWE-94.