Логотип exploitDog
bind:CVE-2020-26048
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-26048

Количество 2

Количество 2

nvd логотип

CVE-2020-26048

больше 5 лет назад

The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within an image extension and through a custom request using the rename function provided by the file manager is able to modify the image extension into PHP resulting in remote arbitrary code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-vg5c-7m9h-9pr2

больше 3 лет назад

The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within an image extension and through a custom request using the rename function provided by the file manager is able to modify the image extension into PHP resulting in remote arbitrary code execution.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-26048

The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within an image extension and through a custom request using the rename function provided by the file manager is able to modify the image extension into PHP resulting in remote arbitrary code execution.

CVSS3: 8.8
2%
Низкий
больше 5 лет назад
github логотип
GHSA-vg5c-7m9h-9pr2

The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within an image extension and through a custom request using the rename function provided by the file manager is able to modify the image extension into PHP resulting in remote arbitrary code execution.

2%
Низкий
больше 3 лет назад

Уязвимостей на страницу