CVE-2020-24986
04.09.2020, 20:15
Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File Manager. It is possible to modify site configuration to upload the PHP file and execute arbitrary commands.Enginsight
Vendor | Product | Version |
---|---|---|
concretecms | concrete_cms | 𝑥 ≤ 8.5.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration