SB2018010302 - PHP code injection in b2evolution
Published: January 3, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2017-1000423)
The vulnerability allows a remote attacker to execute arbitrary PHP code.
The vulnerability exists due to improper input validation (backslash and single quote escape) in basic install functionality. A remote attacker can execute arbitrary PHP code.
Remediation
Install update from vendor's website.