First published: Fri May 05 2023(Updated: )
PHP Remote File Inclusion in GitHub repository unilogies/bumsys prior to 2.1.1.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Bumsys Project Bumsys | <2.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2551 is a vulnerability that allows remote attackers to include arbitrary files via the PHP include function.
CVE-2023-2551 has a severity rating of 8.8, which is considered high.
The GitHub repository unilogies/bumsys prior to version 2.1.1 is affected by CVE-2023-2551.
To fix CVE-2023-2551, you should update the unilogies/bumsys GitHub repository to version 2.1.1 or later.
You can find more information about CVE-2023-2551 in the references provided: https://github.com/unilogies/bumsys/commit/86e29dd23df348ec6075f0c0de8e06b8d9fb0a9a and https://huntr.dev/bounties/5723613c-55c6-4f18-9ed3-61ad44f5de9c.