Headline
GHSA-xcq3-7pf3-5jvc: Cockpit PHP Remote File Inclusion vulnerability
PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3. Users may upload php files through the system file upload utility to obtain remote code execution.
Cockpit PHP Remote File Inclusion vulnerability
Critical severity GitHub Reviewed Published Aug 6, 2023 to the GitHub Advisory Database • Updated Aug 9, 2023
Related news
CVE-2023-4195: Prevent uploading .phps files · Cockpit-HQ/Cockpit@800c05f
PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3.