CVE-2020-20691

An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploading crafted HTML files.
References
Link Resource
https://github.com/monstra-cms/monstra/issues/461 Exploit Issue Tracking Third Party Advisory
https://github.com/monstra-cms/monstra/issues/461 Exploit Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:monstra:monstra_cms:3.0.4:*:*:*:*:*:*:*

History

21 Nov 2024, 05:12

Type Values Removed Values Added
References () https://github.com/monstra-cms/monstra/issues/461 - Exploit, Issue Tracking, Third Party Advisory () https://github.com/monstra-cms/monstra/issues/461 - Exploit, Issue Tracking, Third Party Advisory

Information

Published : 2021-09-27 22:15

Updated : 2024-11-21 05:12


NVD link : CVE-2020-20691

Mitre link : CVE-2020-20691

CVE.ORG link : CVE-2020-20691


JSON object : View

Products Affected

monstra

  • monstra_cms
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type