What the vulnerability does
01Description
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
Explanation of Vulnerability in Simple Terms
CTX Feed versions up to 6.6.42 contain a code injection vulnerability that allows high-privileged users to execute arbitrary PHP code on the site. An attacker with administrative or equivalent access can inject malicious code through the plugin's input handling, affecting confidentiality, integrity, and availability of the entire site. Update to a version newer than 6.6.42 immediately.
What an attacker can do
Run their own PHP code on the site with full system access.
Potential impact on your site
A compromised admin account can execute code affecting the entire site, including data theft, modification, or deletion.
Conditions required to exploit
Attacker must have high-level administrative privileges on the site.
Key dates
External resources
Related vulnerabilities