Guest Entries Remote code execution via file uploads
High severity
GitHub Reviewed
Published
Nov 11, 2023
in
duncanmcclean/guest-entries
•
Updated Nov 15, 2023
Description
Published by the National Vulnerability Database
Nov 13, 2023
Published to the GitHub Advisory Database
Nov 14, 2023
Reviewed
Nov 14, 2023
Last updated
Nov 15, 2023
Impact
When using the file uploads feature, it was possible to upload PHP files.
Patches
The vulnerability is fixed in v3.1.2.
References