What the vulnerability does
01Description
: Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance: from n/a through 1.7.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
: Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance: from n/a through 1.7.2.
Explanation of Vulnerability in Simple Terms
Breakdance versions up to 1.7.2 allow authenticated users with low privileges to inject and execute arbitrary code on the site. An attacker with a low-privilege account can run their own PHP code, potentially compromising the entire site. The vulnerability affects all confidentiality, integrity, and availability of the site.
What an attacker can do
Run arbitrary code on the site with full site access.
Potential impact on your site
A low-privilege user account can compromise the entire site, steal data, or take it offline.
Conditions required to exploit
Attacker needs a low-privilege user account; no user interaction required.
Key dates
External resources
Related vulnerabilities