What the vulnerability does
01Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Saad Iqbal Post Snippets post-snippets allows Remote Code Inclusion.This issue affects Post Snippets: from n/a through <= 4.0.12.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Improper Control of Generation of Code ('Code Injection') vulnerability in Saad Iqbal Post Snippets post-snippets allows Remote Code Inclusion.This issue affects Post Snippets: from n/a through <= 4.0.12.
Explanation of Vulnerability in Simple Terms
Post Snippets versions 4.0.12 and earlier contain a code injection vulnerability. An attacker with low-level user privileges can inject and execute arbitrary PHP code on the site by manipulating input that is not properly sanitized. The vulnerability has a wide scope, potentially affecting other components or users on the site.
What an attacker can do
Run their own PHP code on the site with the privileges of the web server.
Potential impact on your site
An attacker with basic user access can compromise your entire site, steal data, modify content, or install malware.
Conditions required to exploit
Attacker must have a low-level user account (e.g., contributor or subscriber role) on the site.
Key dates
External resources
Related vulnerabilities