CVE-2020-26678
26.05.2021, 12:15
vFairs 3.3 is affected by Remote Code Execution. Any user logged in to a vFairs virtual conference or event can abuse the functionality to upload a profile picture in order to place a malicious PHP file on the server and gain code execution.Enginsight
Vendor | Product | Version |
---|---|---|
vfairs | vfairs | 3.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References