Impact
Incorrect regular expressions allow to upload PHP scripts to config/templates/pdf. This vulnerability could lead to a Remote Code Execution if the
/config/templates/pdf/ directory is accessible for remote users. This is not a default configuration of LAM.
Patches
The issue is fixed in version 8.0.
Workarounds
None
For more information
If you have any questions or comments about this advisory:
Credits
Arseniy Sharoglazov and Andrey Medov
Impact
Incorrect regular expressions allow to upload PHP scripts to config/templates/pdf. This vulnerability could lead to a Remote Code Execution if the
/config/templates/pdf/ directory is accessible for remote users. This is not a default configuration of LAM.
Patches
The issue is fixed in version 8.0.
Workarounds
None
For more information
If you have any questions or comments about this advisory:
Credits
Arseniy Sharoglazov and Andrey Medov