First published: Mon Oct 11 2021(Updated: )
PHPFusion 9.03.110 is affected by a remote code execution vulnerability. The theme function will extract a file to "webroot/themes/{Theme Folder], where an attacker can access and execute arbitrary code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Php-fusion Phpfusion | =9.03.110 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-40189.
The severity of CVE-2021-40189 is high, with a severity value of 7.2.
CVE-2021-40189 affects PHPFusion 9.03.110 by allowing a remote code execution vulnerability.
An attacker can exploit CVE-2021-40189 by accessing and executing arbitrary code through the file extracted to 'webroot/themes/{Theme Folder]'.
At the time of writing, there is no fix available for CVE-2021-40189. It is recommended to update to a version of PHPFusion that is not affected.