Skip to main content

Protection Mechanism Failure

CVE-2021-46433

Severity High
Score 10/10

Summary

In fenom there is a way in fenom/src/Fenom/Template.php function getTemplateCode() to bypass sandbox to execute arbitrary PHP code when disable_native_funcs is true.

  • LOW
  • NETWORK
  • HIGH
  • CHANGED
  • NONE
  • NONE
  • HIGH
  • HIGH

CWE-693 - Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Advisory Timeline

  • Published