What the vulnerability does
01Description
Improper Control of Generation of Code ('Code Injection') vulnerability in David F. Carr RSVPMaker.This issue affects RSVPMaker: from n/a through 10.6.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Improper Control of Generation of Code ('Code Injection') vulnerability in David F. Carr RSVPMaker.This issue affects RSVPMaker: from n/a through 10.6.6.
Explanation of Vulnerability in Simple Terms
RSVPMaker versions up to 10.6.6 contain a code injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP code on the server without user interaction. The vulnerability stems from improper handling of user input, enabling remote code execution with full system impact. Current version 12.1 is not affected.
What an attacker can do
Run arbitrary PHP code on the server and take complete control of the site.
Potential impact on your site
Complete compromise of the site, including data theft, malware installation, and site defacement.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities