In PluxXml V5.7,the theme edit function /PluXml/core/admin/parametres_edittpl.php allows remote attackers to execute arbitrary PHP code by placing this code into a template.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pluxxml | Pluxxml | 5.7 (including) | 5.7 (including) |
Pluxml | Ubuntu | bionic | * |
Pluxml | Ubuntu | groovy | * |
Pluxml | Ubuntu | hirsute | * |
Pluxml | Ubuntu | impish | * |
Pluxml | Ubuntu | trusty | * |
Pluxml | Ubuntu | xenial | * |