Vulnerabilities > CVE-2019-9829 - Inclusion of Functionality from Untrusted Control Sphere vulnerability in Maccms 10.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a template/default_pc/html/art Edit action. This occurs because template rendering uses an include operation on a cache file, which bypasses the prohibition of .php files as templates.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |