Vulnerability Description
In Gxlcms QY v1.0.0713, the update function in Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to execute arbitrary PHP code by placing this code into a template.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gxlcms | Gxlcms Qy | 1.0.0713 |
Related Weaknesses (CWE)
References
- http://www.atksec.com/cve/GxlcmsQY-v1.0.0713-update-template-getshell/index.htmlExploitThird Party Advisory
- http://www.atksec.com/cve/GxlcmsQY-v1.0.0713-update-template-getshell/index.htmlExploitThird Party Advisory
FAQ
What is CVE-2018-9847?
CVE-2018-9847 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In Gxlcms QY v1.0.0713, the update function in Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to execute arbitrary PHP code by placing this code into a template.
How severe is CVE-2018-9847?
CVE-2018-9847 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-9847?
Check the references section above for vendor advisories and patch information. Affected products include: Gxlcms Gxlcms Qy.