Medium
CVSS 6.0
Overview
The Ubercart module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer product classes" permission to execute arbitrary PHP code via unspecified vectors.
The Ubercart module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticate...
The Ubercart module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer product classes" permission to execute arbitrary PHP code via unspecified vectors.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: