Vulnerabilities > Vscode Phpmd Project

DATE CVE VULNERABILITY TITLE RISK
2021-07-30 CVE-2021-30124 Command Injection vulnerability in Vscode-PHPmd Project Vscode-PHPmd
The unofficial vscode-phpmd (aka PHP Mess Detector) extension before 1.3.0 for Visual Studio Code allows remote attackers to execute arbitrary code via a crafted phpmd.command value in a workspace folder.
network
low complexity
vscode-phpmd-project CWE-77
7.5