QR/demoapp/qr_image.php in Asial JpGraph Professional...
Moderate severity
Unreviewed
Published
Jul 4, 2024
to the GitHub Advisory Database
•
Updated Aug 1, 2024
Description
Published by the National Vulnerability Database
Jul 4, 2024
Published to the GitHub Advisory Database
Jul 4, 2024
Last updated
Aug 1, 2024
QR/demoapp/qr_image.php in Asial JpGraph Professional through 4.2.6-pro allows remote attackers to execute arbitrary code via a PHP payload in the data parameter in conjunction with a .php file name in the filename parameter. This occurs because an unnecessary QR/demoapp folder.is shipped with the product.
References