vendor:
Stadtportal
by:
9
CVSS
CRITICAL
Arbitrary Code Execution
94
CWE
Product Name: Stadtportal
Affected Version From: 4
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:easyins:stadtportal:4
Platforms Tested:
Arbitrary Code Execution in EasyIns Stadtportal
The vulnerability allows an attacker to include malicious files containing arbitrary code to be executed on a vulnerable computer. By manipulating the 'site' parameter in the 'index.php' file, the attacker can provide a URL to a malicious file hosted on their server, which will then be executed on the target system.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of EasyIns Stadtportal.