juzawebCMS Injection vulnerability
High severity
GitHub Reviewed
Published
Oct 28, 2023
to the GitHub Advisory Database
•
Updated Jan 9, 2024
Description
Published by the National Vulnerability Database
Oct 28, 2023
Published to the GitHub Advisory Database
Oct 28, 2023
Reviewed
Jan 9, 2024
Last updated
Jan 9, 2024
An issue in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted file to the custom plugin function.
References