Skip to content

Arbitrary class inclusion

Moderate
cklosowski published GHSA-x2p7-63f5-c2hp Aug 21, 2020

Package

No package listed

Affected versions

2.4 > 2.9.23

Patched versions

2.9.24

Description

Impact

Arbitrary class inclusion in the batch processing API.

Patches

Version 2.9.24 contains a remedy to the ability to execute an arbitrary class.

Workarounds

While there is not a workaround, avoiding having any users who have access to the administrative area of EDD's tools.

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

No known CVE

Weaknesses

No CWEs