BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-modules/forms/process.php.
References
Link Resource
https://github.com/bigtreecms/BigTree-CMS/issues/342 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-09-14T02:00:00

Updated: 2018-09-14T02:57:01

Reserved: 2018-09-13T00:00:00


Link: CVE-2018-17030

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-09-14T02:29:00.280

Modified: 2018-11-07T16:41:31.153


Link: CVE-2018-17030

JSON object: View

cve-icon Redhat Information

No data.

CWE