CVE-2021-30124

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/07/2021
Last modified:
28/06/2022

Description

The unofficial vscode-phpmd (aka PHP Mess Detector) extension before 1.3.0 for Visual Studio Code allows remote attackers to execute arbitrary code via a crafted phpmd.command value in a workspace folder.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vscode-phpmd_project:vscode-phpmd:*:*:*:*:*:visual_studio_code:*:* 1.3.0 (excluding)