Impact
An authenticated user that has access to standard interface can craft an URL that can be used to execute a system command.
Patches
Upgrade to 2.10.1.
Workarounds
Delete the ajax/dropdownContact.php
file from the plugin.
For more information
If you have any questions or comments about this advisory, mail us at [email protected].
Impact
An authenticated user that has access to standard interface can craft an URL that can be used to execute a system command.
Patches
Upgrade to 2.10.1.
Workarounds
Delete the
ajax/dropdownContact.php
file from the plugin.For more information
If you have any questions or comments about this advisory, mail us at [email protected].