Arbitrary shell execution
High severity
GitHub Reviewed
Published
Mar 26, 2022
to the GitHub Advisory Database
•
Updated Jan 11, 2023
Package
Affected versions
>= 1.0.0, < 2.8.1
Patched versions
2.8.1
Description
Published to the GitHub Advisory Database
Mar 26, 2022
Reviewed
Mar 26, 2022
Last updated
Jan 11, 2023
Uses of shell_exec() and exec() were not escaping filenames and configuration settings in most cases
References