header-logo
Suggest Exploit
vendor:
CakePHP
by:
Gjoko Krstic
9,8
CVSS
CRITICAL
Remote Code Execution
78
CWE
Product Name: CakePHP
Affected Version From: 3.7.12
Affected Version To: 3.9.1
Patch Exists: YES
Related CWE: CVE-2019-15107
CPE: a:cakephp:cakephp
Other Scripts: N/A
Platforms Tested: None
2019

CakePHP Remote Code Execution Vulnerability

Webmin <=1.920. is vulnerable to an unauthenticated remote command execution via the parameter 'old' in password_change.cgi.

Mitigation:

Upgrade to CakePHP version 3.7.13, 3.8.11, or 3.9.2.
Source

Exploit-DB raw data: