Vulnerabilities > A51Dev

DATE CVE VULNERABILITY TITLE RISK
2013-05-23 CVE-2012-6554 Improper Input Validation vulnerability in A51Dev Activecollab Chat Module
functions/html_to_text.php in the Chat module before 1.5.2 for activeCollab allows remote authenticated users to execute arbitrary PHP code via the message[message_text] parameter to chat/add_messag, which is not properly handled when executing the preg_replace function with the eval switch.
network
low complexity
a51dev CWE-20
6.5