CRITICAL
An issue was discovered in Elefant CMS before 2.0.7
Published Sep 12, 2018
9.8
CRITICALCVSS 3.0
EPSS 3.73%
Description
An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/stylesheet.php by using a .php extension in the New Stylesheet Name field in conjunction with <?php content, because of insufficient input validation in apps/designer/handlers/csspreview.php.
Affected products
No data.
- < 2.0.7
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://github.com/advisories/GHSA-x2w2-qgv6-8xrm Advisory
- https://github.com/jbroadway/elefant/commit/0795ab57c7ffa53ff4af57e229f6d9680fa54a21 x_refsource_MISCPatchThird Party Advisory
- https://github.com/jbroadway/elefant/issues/286 x_refsource_MISCExploitPatchThird Party Advisory
- https://github.com/jbroadway/elefant/releases/tag/elefant_2_0_7_stable x_refsource_MISCRelease Notes
- https://nvd.nist.gov/vuln/detail/CVE-2018-16975
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-x2w2-qgv6-8xrm | Advisory | |
| https://github.com/jbroadway/elefant/commit/0795ab57c7ffa53ff4af57e229f6d9680fa54a21 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/jbroadway/elefant/issues/286 | x_refsource_MISCExploitPatchThird Party Advisory | |
| https://github.com/jbroadway/elefant/releases/tag/elefant_2_0_7_stable | x_refsource_MISCRelease Notes | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-16975 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 12, 2018
Updated Aug 5, 2024
Reserved Sep 12, 2018
Link CVE-2018-16975
CISA Vulnrichment
GHSA-X2W2-QGV6-8XRM Updated n/a