Executive brief
Pheditor, a web-based file manager and editor, contains a security flaw in its built-in terminal feature. An authorized user can bypass security restrictions to run unauthorized commands on the underlying server. This could allow an attacker to view sensitive files, modify website data, or take full control of the web server.
Technical details
The vulnerability is an OS command injection (CWE-78) resulting from incomplete sanitization of user input in the terminal feature. While previous patches blocked characters like '