Medium
CVSS 6.5
Overview
Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting the code into the email parameter to (1) subscribe.php or (2) unsubscribe.php.
Open Newsletter 2.5 and earlier allows remote authenticated administrators to ex...
Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting the code into the email parameter to (1) subscribe.php or (2) unsubscribe.php.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: