A vulnerability was identified in code-projects Chamber of Commerce Membership Management System 1.0. Impacted is the function fwrite of the file admin/pageMail.php. The manipulation of the argument mailSubject/mailMessage leads to command injection.
The attack may be initiated remotely. The exploit is publicly available and might be used.
Attack Parameters
Impact Assessment
CVSS Vector v4.0