CVE-2020-25406

app\admin\controller\sys\Uploads.php in lemocms 1.8.x allows users to upload files to upload executable files.
References
Link Resource
https://www.misakikata.com/codes/File%20Upload.html Exploit Third Party Advisory
https://www.misakikata.com/codes/File%20Upload.html Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:lemocms:lemocms:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:17

Type Values Removed Values Added
References () https://www.misakikata.com/codes/File%20Upload.html - Exploit, Third Party Advisory () https://www.misakikata.com/codes/File%20Upload.html - Exploit, Third Party Advisory

Information

Published : 2020-11-18 16:15

Updated : 2024-11-21 05:17


NVD link : CVE-2020-25406

Mitre link : CVE-2020-25406

CVE.ORG link : CVE-2020-25406


JSON object : View

Products Affected

lemocms

  • lemocms
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type