
capture0x/Phoenix
Releases0
Stars2
CE Phoenix v1.0.8.20 - Remote Code Execution (RCE) (Authenticated)
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 4.8 MEDIUM | — | ||
HTML Injection vulnerability in CE Phoenix v1.0.8.20 and before allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted payload to the english.php component. | |||
| 7.2 HIGH | — | ||
A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary PHP code via injecting a crafted payload into the file english.php. | |||