What the vulnerability does
01Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Sala. This issue affects Sala: from n/a through 1.1.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Sala. This issue affects Sala: from n/a through 1.1.6.
Explanation of Vulnerability in Simple Terms
Sala versions up to 1.1.6 contain a vulnerability that allows an attacker to read sensitive data, modify content, or disrupt service. The attack requires network access and high technical complexity but no authentication. The exact attack mechanism is unclear due to incomplete vulnerability classification data.
What an attacker can do
Read sensitive data, modify content, or disrupt the service without authentication.
Potential impact on your site
Confidential data may be exposed, content may be altered, or the service may become unavailable.
Conditions required to exploit
Network access; high technical complexity to exploit; no authentication required.
Key dates
External resources
Related vulnerabilities