An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/stylesheet.php
by using a .php
extension in the New Stylesheet Name field in conjunction with <?php
content, because of insufficient input validation in apps/designer/handlers/csspreview.php
.
{ "nvd_published_at": "2018-09-12T21:29:00Z", "cwe_ids": [ "CWE-94" ], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-04-23T22:56:57Z" }