Vulnerabilities (CVE)

Filtered by vendor Maracms Subscribe
Filtered by product Maracms
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-25042 1 Maracms 1 Maracms 2024-11-21 6.5 MEDIUM 7.2 HIGH
An arbitrary file upload issue exists in Mara CMS 7.5. In order to exploit this, an attacker must have a valid authenticated (admin/manager) session and make a codebase/dir.php?type=filenew request to upload PHP code to codebase/handler.php.