vendor:
NodCMS
by:
Ashiyane Digital Security Team
7.5
CVSS
HIGH
PHP Code Execution
94
CWE
Product Name: NodCMS
Affected Version From: All Version
Affected Version To: All Version
Patch Exists: NO
Related CWE:
CPE: a:nodcms
Platforms Tested: Windows 10
2016
NodCMS – PHP Code Execution
The NodCMS application is vulnerable to PHP Code Execution. An attacker can exploit this vulnerability by injecting malicious code into the 'config.php' file, which can lead to remote code execution.
Mitigation:
The vendor should release a patch to fix this vulnerability. In the meantime, users are advised to restrict access to the 'config.php' file and regularly update their NodCMS installation.