CVE 6.9 MEDIUM

php-censor Webhook Endpoint GitBuild.php os command injection_CVE-2026-10273

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBuild.php of the component Webhook Endpoint. Performing a manipulation of the argument commitId results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named cd68d102601320bd319d590b75f7652e66f0685f. It is recommended to apply a patch to fix this issue.

Basic Information

ID CVE-2026-10273
Source VulDB
Published Jun 1, 2026 at 16:15

Affected Product

Vendor n/a
Product php-censor
Version 2.1.0
Affected Versions n/a php-censor 2.1.0
n/a php-censor 2.1.1
n/a php-censor 2.1.2
n/a php-censor 2.1.3
n/a php-censor 2.1.4
n/a php-censor 2.1.5
n/a php-censor 2.1.6

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.