QID 995456
Date Published: 2023-10-03
QID 995456: PHP (Composer) Security Update for gugoan/economizzer (GHSA-pq98-6hf6-3rj3)
A remote code execution (RCE) vulnerability via an insecure file upload exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023). A malicious attacker can upload a PHP web shell as an attachment when adding a new cash book entry. Afterwards, the attacker may visit the web shell and execute arbitrary commands.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-pq98-6hf6-3rj3 for updates and patch information.
Vendor References
- GHSA-pq98-6hf6-3rj3 -
github.com/advisories/GHSA-pq98-6hf6-3rj3
CVEs related to QID 995456
Software Advisories
| Advisory ID | Software | Component | Link |
|---|