CVE-2021-46433
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/03/2022
Last modified:
04/04/2022
Description
In fenom 2.12.1 and before, there is a way in fenom/src/Fenom/Template.php function getTemplateCode()to bypass sandbox to execute arbitrary PHP code when disable_native_funcs is true.
Impact
Base Score 3.x
10.00
Severity 3.x
CRITICAL
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:fenom_project:fenom:*:*:*:*:*:*:*:* | 2.12.1 (including) |
To consult the complete list of CPE names with products and versions, see this page



