CVE-2014-125116 Details
Description
A remote code execution vulnerability exists in HybridAuth versions 2.0.9 through 2.2.2 due to insecure use of the install.php installation script. The script remains accessible after deployment and fails to sanitize input before writing to the application’s config.php file. An unauthenticated attacker can inject arbitrary PHP code into config.php, which is later executed when the file is loaded. This allows attackers to achieve remote code execution on the server. Exploitation of this issue will overwrite the existing configuration, rendering the application non-functional.
A remote code execution vulnerability has been identified in HybridAuth versions 2.0.9 prior to 2.2.2. The issue arises from the installation script 'install.php', which remains accessible after deployment and does not properly sanitize input before writing to the application's 'config.php' file. This flaw allows an unauthenticated attacker to inject arbitrary PHP code into 'config.php', which is executed when the file is loaded. The exploitation overwrites the existing configuration, causing the application to malfunction.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 25, 2025CISA-ADP
Assessed Jul 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| HybridAuth | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 29, 2025 | CVE Modified | CISA-ADP |
| Jul 25, 2025 | New CVE Received | [email protected] |
Volerion