Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-fjx5-xm7q-whvj: CraftCMS allows remote attacker to execute arbitrary code via crafted script to Section parameter

An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter.

ghsa
#git

CraftCMS allows remote attacker to execute arbitrary code via crafted script to Section parameter

Moderate severity GitHub Reviewed Published May 12, 2023 to the GitHub Advisory Database • Updated May 12, 2023

Related news

CVE-2023-30130: Craft CMS

An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter.