Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

The Local File Inclusion vulnerability in /system/WCore/WHelper.php #152

Closed
LessonXK opened this issue Jun 8, 2018 · 3 comments
Closed

Comments

@LessonXK
Copy link

LessonXK commented Jun 8, 2018

I found a local file inclusion vulnerability.An attacker might include local PHP files or read non-PHP files with this vulnerability.

Reference:
https://xkklq.coding.me/2018/06/07/wityCMS-LFI/

@JohanDufau
Copy link
Member

Hello,
Thank you for reporting this back!

Here are two fixes:
On helpers inclusion: 66b46b3
On roxy: 4bb5b26

What do you think?

@LessonXK
Copy link
Author

I confirm that the vulnerability has been fixed

@JohanDufau
Copy link
Member

Great! I will release v0.6.3 with this fix this week.
Thanks again!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants