In fenom 2.12.1 and before, there is a way in fenom/src/Fenom/Template.php function getTemplateCode()to bypass sandbox to execute arbitrary PHP code when disable_native_funcs is true.
References
Link | Resource |
---|---|
https://github.com/fenom-template/fenom/issues/331 | Issue Tracking Third Party Advisory |
Configurations
History
No history.
Information
Published : 2022-03-28 11:15
Updated : 2022-04-04 20:32
NVD link : CVE-2021-46433
Mitre link : CVE-2021-46433
CVE.ORG link : CVE-2021-46433
JSON object : View
Products Affected
fenom_project
- fenom
CWE