CVE-2023-47621

Guest Entries is a php library which allows users to create, update & delete entries from the front-end of a site. In affected versions the file uploads feature did not prevent the upload of PHP files. This may lead to code execution on the server by authenticated users. This vulnerability is fixed in v3.1.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:duncanmcclean:guest_entries:*:*:*:*:*:*:*:*

History

21 Nov 2023, 03:10

Type Values Removed Values Added
References () https://github.com/duncanmcclean/guest-entries/commit/a8e17b4413bfbbc337a887761a6c858ef1ddb4da - () https://github.com/duncanmcclean/guest-entries/commit/a8e17b4413bfbbc337a887761a6c858ef1ddb4da - Patch
References () https://github.com/duncanmcclean/guest-entries/security/advisories/GHSA-rw82-mhmx-grmj - () https://github.com/duncanmcclean/guest-entries/security/advisories/GHSA-rw82-mhmx-grmj - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
First Time Duncanmcclean
Duncanmcclean guest Entries
CPE cpe:2.3:a:duncanmcclean:guest_entries:*:*:*:*:*:*:*:*
CWE CWE-434

13 Nov 2023, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-13 20:15

Updated : 2023-11-21 03:10


NVD link : CVE-2023-47621

Mitre link : CVE-2023-47621


JSON object : View

Products Affected

duncanmcclean

  • guest_entries
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type