In fenom 2.12.1 and before, there is a way in fenom/src/Fenom/Template.php function getTemplateCode()to bypass sandbox to execute arbitrary PHP code when disable_native_funcs is true.
References
Link | Resource |
---|---|
https://github.com/fenom-template/fenom/issues/331 | Issue Tracking Third Party Advisory |
Configurations
Information
Published : 2022-03-28 04:15
Updated : 2022-04-04 13:32
NVD link : CVE-2021-46433
Mitre link : CVE-2021-46433
JSON object : View
CWE
Products Affected
fenom_project
- fenom