SocialEngine (SE) before 2.83 grants certain write privileges for templates, which allows remote authenticated administrators to execute arbitrary PHP code.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/43959http://www.securityfocus.com/archive/1/494638/100/0/threadedhttp://www.socialengine.net/news.phphttp://securityreason.com/securityalert/4035http://secunia.com/advisories/31203