High
CVSS 7.5
Overview
The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers to create and execute PHP files.
The calendar module for phpgroupware 0.9.14 does not enforce the "save extension...
The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers to create and execute PHP files.
This vulnerability is rated 🟠 HIGH.
Recommended actions: