Back

HIGH

An issue was discovered in SDCMS 1.6 with PHP 5.x

Published Nov 25, 2018

Description

An issue was discovered in SDCMS 1.6 with PHP 5.x. app/admin/controller/themecontroller.php uses a check_bad function in an attempt to block certain PHP functions such as eval, but does not prevent use of preg_replace 'e' calls, allowing users to execute arbitrary code by leveraging access to admin template management.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 25, 2018
Updated Aug 5, 2024
Reserved Nov 25, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a