CVE-2020-24986 – Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type …

Vuln ID: CVE-2020-24986

Published:  2020-09-04  20:15:11Z

Description: Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File Manager. It is possible to modify site configuration to upload the PHP file and execute arbitrary commands.

Source: NVD.NIST.GOV

 


Date:

Categorie(s):

Tag(s):