Orbit Fox by ThemeIsle, 014073fa-7949-49e8-996f-2f84dab94ba9
- CVE, Research URL
- Home page URL
- Application
- Published on
- -
- Research Description
- Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.6.4 Orbit Fox by ThemeIsle <= 2.6.3 -Does not properly Authenticate REST API Calls Orbit Fox by Themeisle (aka Themeisle Companion) version <= 2.6.3 does not properly authenticate REST API calls allowing unauthenticated users to execute several API calls. In some cases one of these calls can be used to upload arbitrary files which can lead to remote code execution.
- Affected versions
-
max 2.6.4.
- Status
-
vulnerable