cve/2021/CVE-2021-40373.md
2024-05-25 21:48:12 +02:00

1.0 KiB

CVE-2021-40373

Description

playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then executing that code via the index.php?app=main&inc=core_welcome URI.

POC

Reference

No PoCs from references.

Github