Unrated severityNVD Advisory· Published Dec 19, 2014· Updated May 6, 2026
CVE-2014-9185
CVE-2014-9185
Description
Static code injection vulnerability in install.php in Morfy CMS 1.05 allows remote authenticated users to inject arbitrary PHP code into config.php via the site_url parameter.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5News mentions
0No linked articles in our index yet.