PHP Object injection -> Building Custom Gadget chain -> RCE
High
E
ExpressionEngine
Submitted None
Team Summary
Official summary from ExpressionEngine
When signed into the control panel with permissions, this researcher was able to build a custom Gadget chain, which led to remote code execution.
Actions:
Reported by
karezma
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Command Injection - Generic