CVE-2012-6554: a51dev Activecollab Chat Module

Medium severity, CVSS 6.5. EPSS: 16.7% chance of exploitation in the next 30 days.

functions/html_to_text.php in the Chat module before 1.5.2 for activeCollab allows remote authenticated users to execute arbitrary PHP code via the message[message_text] parameter to chat/add_messag, which is not properly handled when executing the preg_replace function with the eval switch.

Affected products

  • a51dev Activecollab Chat Module: version 1.0 only; version 1.1 only; version 1.1.1 only; version 1.2 only; version 1.3 only; version 1.3.2 only; …

Published 2013-05-23. Last modified 2026-06-16.