BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-modules/forms/process.php.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-09-14T02:00:00

Updated: 2024-08-05T10:39:59.262Z

Reserved: 2018-09-13T00:00:00

Link: CVE-2018-17030

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-09-14T02:29:00.280

Modified: 2018-11-07T16:41:31.153

Link: CVE-2018-17030

cve-icon Redhat

No data.