Summary
A critical remote code execution (RCE) vulnerability exists in the superfecta module due to unsafe inclusion of arbitrary PHP files, allowing authenticated attackers to execute arbitrary PHP code on the server with the privileges of the web server user.
Authentication with a known username is required.
Common Vulnerabilities and Exposures (CVE)
Requested
GitHub Security Advisory (GHSA)
GHSA-j53p-5m8r-j3p6
Provider Urgency (choice of: Not Defined, Clear, Green, Amber, or Red)
G - Green