Описание
Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /themes directory via a crafted zip file uploaded to the Themes panel.
Ссылки
- Third Party Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
- Release NotesThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:fork-cms:fork_cms:5.9.2:*:*:*:*:*:*:*
EPSS
Процентиль: 62%
0.00423
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-434
Связанные уязвимости
EPSS
Процентиль: 62%
0.00423
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-434