Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Issue #331

Open
altm4n opened this issue Jan 19, 2022 · 3 comments
Open

Security Issue #331

altm4n opened this issue Jan 19, 2022 · 3 comments

Comments

@altm4n
Copy link

altm4n commented Jan 19, 2022

Hi,
In fenom 2.12.1 and before ,there is a way to bypass sandbox to exec arbitrary php code when disable_native_funcs is true.

@WinterSilence
Copy link
Contributor

GHSA-674v-3g2w-84gx

@yatlib
Copy link

yatlib commented Sep 7, 2024

Any updates?

@bzick
Copy link
Member

bzick commented Sep 8, 2024

I can't reproduce the issue. Seems a bullshit. Yes, fenom can call controlled eval, it's normal

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants