PGTStorage/pgt-file.php in phpCAS before 1.1.3, when...
Low severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Oct 7, 2010
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Feb 1, 2023
PGTStorage/pgt-file.php in phpCAS before 1.1.3, when proxy mode is enabled, allows local users to overwrite arbitrary files via a symlink attack on an unspecified file.
References