Critical
CVSS 9.3
Overview
PHP remote file inclusion vulnerability in calendar.php in WorkSimple 1.2.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter.
PHP remote file inclusion vulnerability in calendar.php in WorkSimple 1.2.1, whe...
PHP remote file inclusion vulnerability in calendar.php in WorkSimple 1.2.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter.
This vulnerability is rated 🔴 CRITICAL.
Recommended actions: