Description
Chevereto 3.13.4 Core contains a remote code execution vulnerability that allows attackers to inject malicious code during database configuration installation. Attackers can manipulate the database table prefix parameter to write a PHP shell file and execute arbitrary system commands through a crafted POST request.
Problem types
Improper Control of Generation of Code ('Code Injection')
Product status
Credits
Jinny Ramsmark
References
www.exploit-db.com/exploits/47903 (ExploitDB-47903)
chevereto.com/ (Chevereto Official Homepage)
github.com/Chevereto/Chevereto-Free/releases (Chevereto Free GitHub Releases)
www.vulncheck.com/...es/chevereto-core-remote-code-execution (VulnCheck Advisory: Chevereto 3.13.4 Core - Remote Code Execution)