{"id":"GHSA-rggc-4g3r-j7ff","summary":"Remote Code Execution in Contao Managed Edition","details":"Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.","aliases":["CVE-2022-26265"],"modified":"2023-11-08T04:08:53.736858Z","published":"2022-03-20T00:00:30Z","database_specific":{"nvd_published_at":"2022-03-18T23:15:00Z","cwe_ids":["CWE-77"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2022-03-28T16:23:06Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-26265"},{"type":"WEB","url":"https://github.com/JCCD/Contao-Managed-Edition-1.5-RCE/blob/main/VulnerabilityDetails.md"},{"type":"PACKAGE","url":"https://github.com/contao/managed-edition"}],"affected":[{"package":{"name":"contao/managed-edition","ecosystem":"Packagist","purl":"pkg:composer/contao/managed-edition"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.5.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-rggc-4g3r-j7ff/GHSA-rggc-4g3r-j7ff.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}