CVE-2020-28173
31.03.2021, 13:15
Simple College Website 1.0 allows a user to conduct remote code execution via /alumni/admin/ajax.php?action=save_settings when uploading a malicious file using the image upload functionality, which is stored in /alumni/admin/assets/uploads/.Enginsight
Vendor | Product | Version |
---|---|---|
simple_college_project | simple_college | 1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration