PHPFusion 9.03.110 is affected by a remote code execution vulnerability. The theme function will extract a file to "webroot/themes/{Theme Folder], where an attacker can access and execute arbitrary code.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-10-11T18:27:33

Updated: 2024-08-04T02:27:31.850Z

Reserved: 2021-08-30T00:00:00

Link: CVE-2021-40189

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-10-11T19:15:07.587

Modified: 2021-10-19T01:09:59.257

Link: CVE-2021-40189

cve-icon Redhat

No data.