CVE-2023-47621

Guest Entries is a php library which allows users to create, update & delete entries from the front-end of a site. In affected versions the file uploads feature did not prevent the upload of PHP files. This may lead to code execution on the server by authenticated users. This vulnerability is fixed in v3.1.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:duncanmcclean:guest_entries:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:30

Type Values Removed Values Added
References () https://github.com/duncanmcclean/guest-entries/commit/a8e17b4413bfbbc337a887761a6c858ef1ddb4da - Patch () https://github.com/duncanmcclean/guest-entries/commit/a8e17b4413bfbbc337a887761a6c858ef1ddb4da - Patch
References () https://github.com/duncanmcclean/guest-entries/security/advisories/GHSA-rw82-mhmx-grmj - Vendor Advisory () https://github.com/duncanmcclean/guest-entries/security/advisories/GHSA-rw82-mhmx-grmj - Vendor Advisory

21 Nov 2023, 03:10

Type Values Removed Values Added
First Time Duncanmcclean
Duncanmcclean guest Entries
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-434
CPE cpe:2.3:a:duncanmcclean:guest_entries:*:*:*:*:*:*:*:*
References () https://github.com/duncanmcclean/guest-entries/commit/a8e17b4413bfbbc337a887761a6c858ef1ddb4da - () https://github.com/duncanmcclean/guest-entries/commit/a8e17b4413bfbbc337a887761a6c858ef1ddb4da - Patch
References () https://github.com/duncanmcclean/guest-entries/security/advisories/GHSA-rw82-mhmx-grmj - () https://github.com/duncanmcclean/guest-entries/security/advisories/GHSA-rw82-mhmx-grmj - Vendor Advisory

13 Nov 2023, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-13 20:15

Updated : 2024-11-21 08:30


NVD link : CVE-2023-47621

Mitre link : CVE-2023-47621

CVE.ORG link : CVE-2023-47621


JSON object : View

Products Affected

duncanmcclean

  • guest_entries
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type