Authenticated RCE via page title
Medium
E
ExpressionEngine
Submitted None
Team Summary
Official summary from ExpressionEngine
A vulnerability was identified and fixed that could have allowed authenticated users to execute arbitrary PHP code by manipulating the page title in a specific API call.
Actions:
Reported by
sum-catnip
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Code Injection