capture0x/Phoenix

capture0x/Phoenix

Releases0
Stars2
CE Phoenix v1.0.8.20 - Remote Code Execution (RCE) (Authenticated)

CVE History

CVEPublishedCVSS v3CVSS v2
4.8 MEDIUM

HTML Injection vulnerability in CE Phoenix v1.0.8.20 and before allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted payload to the english.php component.

7.2 HIGH

A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary PHP code via injecting a crafted payload into the file english.php.