2017-06-05 19:00:00
mitre
PUBLISHED
BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json in an uploaded package. This issue exists in coreadminmodulesdeveloperextensionsinstallprocess.php and coreadminmodulesdeveloperpackagesinstallprocess.php. NOTE: the vendor states "You must implicitly trust any package or extension you install as they all have the ability to write PHP files.