PT-2026-83728 · Yaojingang · Geoflow
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:L/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
yaojingang GEOFlow versions prior to 2.1.1
Description
A code injection flaw exists in the Superadmin Theme Editor component within the
preview() function of the app/Http/Controllers/Admin/SiteThemeEditorController.php file. A remote attacker can trigger this issue by manipulating the blade argument.Recommendations
Update to version 2.1.1.
As a temporary mitigation, restrict access to the
preview() function in the Superadmin Theme Editor component.Exploit
Fix
Special Elements Injection
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Geoflow