A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBuild.php of the component Webhook Endpoint. Performing a manipulation of the argument commitId results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named cd68d102601320bd319d590b75f7652e66f0685f. It is recommended to apply a patch to fix this issue.
Metrics
Affected Vendors & Products
References
History
Mon, 01 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBuild.php of the component Webhook Endpoint. Performing a manipulation of the argument commitId results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named cd68d102601320bd319d590b75f7652e66f0685f. It is recommended to apply a patch to fix this issue. | |
| Title | php-censor Webhook Endpoint GitBuild.php os command injection | |
| First Time appeared |
Php-censor
Php-censor php-censor |
|
| Weaknesses | CWE-77 CWE-78 |
|
| CPEs | cpe:2.3:a:php-censor:php-censor:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Php-censor
Php-censor php-censor |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-01T16:15:09.557Z
Reserved: 2026-05-31T14:18:58.741Z
Link: CVE-2026-10273
No data.
Status : Deferred
Published: 2026-06-01T17:16:43.883
Modified: 2026-06-01T17:57:16.380
Link: CVE-2026-10273
No data.
OpenCVE Enrichment
Updated: 2026-06-01T18:30:06Z