Description
In Phproject before version 1.7.8, there's a vulnerability which allows users with access to file uploads to execute arbitrary code. This is patched in version 1.7.8.
References (2)
Core 2
Core References
Mitigation, Third Party Advisory x_refsource_confirm
https://github.com/Alanaktion/phproject/security/advisories/GHSA-4j97-6w6q-gxjx
Patch, Third Party Advisory x_refsource_misc
https://github.com/Alanaktion/phproject/commit/b49d642e035d835f824bd39babd964ec0e3a285f
Scores
CVSS v3
9.9
EPSS
0.0090
EPSS Percentile
75.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Details
CWE
CWE-434
Status
published
Products (1)
phproject/phproject
< 1.7.8
Published
Apr 22, 2020
Tracked Since
Feb 18, 2026