Loading HuntDB...

PHP Object injection -> Building Custom Gadget chain -> RCE

High
E
ExpressionEngine
Submitted None

Team Summary

Official summary from ExpressionEngine

When signed into the control panel with permissions, this researcher was able to build a custom Gadget chain, which led to remote code execution.

Reported by karezma

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Command Injection - Generic