A vulnerability was found in DolphinPHP up to 1.5.1. It...
Critical severity
Unreviewed
Published
Feb 21, 2023
to the GitHub Advisory Database
•
Updated Mar 2, 2023
Description
Published by the National Vulnerability Database
Feb 21, 2023
Published to the GitHub Advisory Database
Feb 21, 2023
Last updated
Mar 2, 2023
A vulnerability was found in DolphinPHP up to 1.5.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file common.php of the component Incomplete Fix CVE-2021-46097. The manipulation of the argument id leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221551.
References