Loading HuntDB...

Authenticated RCE via page title

Medium
E
ExpressionEngine
Submitted None

Team Summary

Official summary from ExpressionEngine

A vulnerability was identified and fixed that could have allowed authenticated users to execute arbitrary PHP code by manipulating the page title in a specific API call.

Reported by sum-catnip

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Code Injection