Skip to content

Chevereto - 1.0.0 Free - 1.1.4 Free, 3.13.4 Core, Remote Code Execution

Notifications You must be signed in to change notification settings

jra89/CVE-2019-19511

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

5 Commits
 
 
 
 

Repository files navigation

CVE-2019-19511

Chevereto - 1.0.0 Free - 1.1.4 Free, <= 3.13.4 Core, Remote Code Execution

Description

installer.php in Chevereto through 1.1.4 Free, and through 3.13.4 Core, allows remote authenticated admins to execute arbitrary PHP code by injecting this code into the setup process and overwriting the settings.php file, which will then contain the injected code. Since settings.php is overwritten, it also resets the application and puts it in a denial of service state until the settings are restored.

Reference

https://github.com/Chevereto/Chevereto-Free/blob/1.1.4/app/install/installer.php#L736

About

Chevereto - 1.0.0 Free - 1.1.4 Free, 3.13.4 Core, Remote Code Execution

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages