CVE-2018-17827

Publication date

2018-10-01 08:00:00

Family

mitre

State

PUBLISHED

Description

HisiPHP 1.0.8 allows remote attackers to execute arbitrary PHP code by editing a plugins name to contain that code. This name is then injected into app/admin/model/AdminPlugins.php.