Arbitrary Code Execution Vulnerability in Webgalamb by Kvk
CVE-2018-19514
9.8CRITICAL
What is CVE-2018-19514?
In Webgalamb versions up to 7.0, an improper handling of user input allows an attacker to perform arbitrary code execution. By exploiting an authentication bypass, an attacker can gain access to administrative functions of the site. This vulnerability enables the attacker to upload a specially crafted CSV file containing malicious code, which is then executed through a PHP eval() expression in the subscriber.php file, potentially compromising the integrity and security of the affected system.
