CVE-2023-28854
moderate-risk
Published 2023-04-03
nophp is a PHP web framework. Prior to version 0.0.1, nophp is vulnerable to shell command injection on httpd user. A patch was made available at commit e5409aa2d441789cbb35f6b119bef97ecc3986aa on 2023-03-30. Users should update index.php to 2023-03-30 or later or, as a workaround, add a function such as `env_patchsample230330.php` to env.php.
Do I need to act?
~
7.6% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.0/10
High
NETWORK
/ LOW complexity
Affected Products (1)
Nophp
Affected Vendors
References (6)
Release Notes
https://github.com/paijp/nophp/releases/tag/v0.0.1
Release Notes
https://github.com/paijp/nophp/releases/tag/v0.0.1
43
/ 100
moderate-risk
Severity
28/34 · Critical
Exploitability
10/34 · Low
Exposure
5/34 · Minimal