Authenticated Superfecta Arbitrary PHP Code Execution (RCE via Unsafe File Inclusion)

Summary

A critical remote code execution (RCE) vulnerability exists in the superfecta module due to unsafe inclusion of arbitrary PHP files, allowing authenticated attackers to execute arbitrary PHP code on the server with the privileges of the web server user.

Authentication with a known username is required.

Common Vulnerabilities and Exposures (CVE)

Requested

GitHub Security Advisory (GHSA)

GHSA-j53p-5m8r-j3p6

Provider Urgency (choice of: Not Defined, Clear, Green, Amber, or Red)

G - Green

Link to Published GHSA with More Details

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.