PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
https://www.yuque.com/g/alipayyz9csdbcdz/zytgq2/vz8ktghkcgvhsdzn/collaborator/join?token=R5phxzuV3w99ndZD | permissions required |
https://gist.github.com/Omoredream/43f60004665e9d9d8c71f7e976261387 | third party advisory |