Flextype v1.0.0-alpha.3 Stored Arbitrary Expression Injection in ExpressionsDirective Allows Arbitrary File Read
Posted by Ron E on Sep 03Description Flextype CMS v1.0.0-alpha.3 contains a stored arbitrary expression
injection vulnerability in the Entries ExpressionsDirective. An
authenticated remote attacker with sufficient privileges to create or
modify entries can persist arbitrary expression syntax within an entry
field. When the affected field is subsequently retrieved or processed,
Flextype passes the stored value to parsers()->expressions()->parse(),
causing the...