THREAT OPS › Threat News › Flextype v1.0.0-alpha.3 Stored Expression Injection Enables PHP Remote Code Execution
Flextype v1.0.0-alpha.3 Stored Expression Injection Enables PHP Remote Code Execution
<p>Posted by Ron E on Sep 03</p>Description<br /> <br /> Flextype CMS v1.0.0-alpha.3 contains a stored code execution vulnerability<br /> caused by the interaction between globally processed entry expressions, the<br /> mutable registry object exposed to expressions, and the PHP entry directive.<br /> <br /> Attacker-controlled entry fields are automatically processed as expressions<br /> during e
Original source: https://seclists.org/fulldisclosure/2026/Sep/24