Open Meetings Filing Application "PROJECT_ROOT" File Inclusion Vulnerability
Description
A vulnerability has been identified in Open Meetings Filing Application, which could be exploited by attackers to execute arbitrary commands. This flaw is due to input validation errors in the "editmeetings/session.php", "email/session.php", "entityproperties/session.php", and "inc/mail.php" scripts that do not validate the "PROJECT_ROOT" parameter, which could be exploited by remote attackers to include malicious files and execute arbitrary commands with the privileges of the web server.
Vulnerable Products
Vulnerable Software: Open Meetings Filing Application