Source |
The Hacker News |
Identifiant |
8644649 |
Date de publication |
2025-01-30 12:51:00 (vue: 2025-01-30 08:08:12) |
Titre |
Unpatched PHP Voyager Flaws Leave Servers Open to One-Click RCE Exploits |
Texte |
Three security flaws have been disclosed in the open-source PHP package Voyager that could be exploited by an attacker to achieve one-click remote code execution on affected instances.
"When an authenticated Voyager user clicks on a malicious link, attackers can execute arbitrary code on the server," Sonar researcher Yaniv Nizry said in a write-up published earlier this week.
The
Three security flaws have been disclosed in the open-source PHP package Voyager that could be exploited by an attacker to achieve one-click remote code execution on affected instances.
"When an authenticated Voyager user clicks on a malicious link, attackers can execute arbitrary code on the server," Sonar researcher Yaniv Nizry said in a write-up published earlier this week.
The |
Notes |
★★★
|
Envoyé |
Oui |
Condensat |
achieve affected arbitrary attacker attackers authenticated been can click clicks code could disclosed earlier execute execution exploited exploits flaws have instances leave link malicious nizry one open package php published rce remote researcher said security server servers sonar source three unpatched user voyager week when write yaniv |
Tags |
|
Stories |
|
Move |
|