Flextype v1.0.0-alpha.3 Stored Expression Injection Enables PHP Remote Code Execution
Posted by Ron E on Sep 03Description Flextype CMS v1.0.0-alpha.3 contains a stored code execution vulnerability
caused by the interaction between globally processed entry expressions, the
mutable registry object exposed to expressions, and the PHP entry directive. Attacker-controlled entry fields are automatically processed as expressions
during entry retrieval. The expression environment exposes the
application's mutable registry() object, allowing an expression...