PT-2026-69425 · Fabrik · Fabrik
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Fabrik versions prior to 4.6.9
Description
An unauthenticated attacker can execute arbitrary code by leveraging the
ajax calc feature within the calc plugin.Recommendations
Update to version 4.6.9 or later.
As a temporary workaround, restrict access to the
ajax calc feature of the calc plugin.Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fabrik