CVE-2023-47621
CVSS V2 None
CVSS V3 None
Description
Guest Entries is a php library which allows users to create, update & delete entries from the front-end of a site. In affected versions the file uploads feature did not prevent the upload of PHP files. This may lead to code execution on the server by authenticated users. This vulnerability is fixed in v3.1.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Overview
- CVE ID
- CVE-2023-47621
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-11-13T20:02:22.652Z
- Last Modified Date
- 2023-11-13T20:02:22.652Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/duncanmcclean/guest-entries/security/advisories/GHSA-rw82-mhmx-grmj | x_refsource_CONFIRM |
https://github.com/duncanmcclean/guest-entries/commit/a8e17b4413bfbbc337a887761a6c858ef1ddb4da | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-47621 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-47621 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 09:10:05 | Added to TrackCVE |