CVE-2019-13956: Code Injection
Published Jul 18, 2019
·Updated
Discuz!ML 3.2 through 3.4 allows remote attackers to execute arbitrary PHP code via a modified language cookie, as demonstrated by changing 4gH40df5language=en to 4gH40df5language=en'.phpinfo().'; (if the random prefix 4gH40df5 were used).
Affected Software
1 affected component
Codersclub Discuz\!ml>=3.2<=3.4
Event History
Jul 18, 2019
CVE Published
via MITRE·05:23 PM
Data Sourced
via MITRE·05:23 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13956?
CVE-2019-13956 has a high severity rating due to the capability for remote code execution.
2
How do I fix CVE-2019-13956?
To fix CVE-2019-13956, upgrade DiscuZ!ML to version 3.5 or later where the vulnerability is patched.
3
What are the potential risks of CVE-2019-13956?
The risks include unauthorized remote code execution, which can lead to full system compromise.
4
In which versions of Discuz!ML is CVE-2019-13956 present?
CVE-2019-13956 is present in Discuz!ML versions 3.2 through 3.4.
5
Can this vulnerability be exploited without authentication in CVE-2019-13956?
Yes, CVE-2019-13956 can be exploited by remote attackers without the need for authentication.