Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-xcq3-7pf3-5jvc: Cockpit PHP Remote File Inclusion vulnerability

PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3. Users may upload php files through the system file upload utility to obtain remote code execution.

ghsa
#vulnerability#git#php#rce

Cockpit PHP Remote File Inclusion vulnerability

Critical severity GitHub Reviewed Published Aug 6, 2023 to the GitHub Advisory Database • Updated Aug 9, 2023

Related news

CVE-2023-4195: Prevent uploading .phps files · Cockpit-HQ/Cockpit@800c05f

PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3.