What the vulnerability does
01Description
Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
Explanation of Vulnerability in Simple Terms
Advanced Views versions 3.8.11 and earlier contain a code injection vulnerability that allows authenticated users with low privileges to inject and execute arbitrary code on the site. The vulnerability has a wide scope of impact, potentially affecting confidentiality, integrity, and availability of the entire system. No user interaction is required to exploit this issue.
What an attacker can do
Run arbitrary code on the site with the privileges of the web server.
Potential impact on your site
A low-privilege user account can compromise the entire site, including data theft, malware injection, and service disruption.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the site.
Key dates
External resources
Related vulnerabilities