admin/app/mediamanager in Schlix CMS 2.1.8-7 allows Authenticated Unrestricted File Upload, leading to remote code execution. NOTE: "While inadvertently allowing a PHP file to be uploaded via Media Manager was an oversight, it still requires an admin permission. We think it's pretty rare for an administrator to exploit a bug on his/her own site to own his/her own site.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 20 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T22:40:16.048Z
Reserved: 2019-04-08T00:00:00.000Z
Link: CVE-2019-11021
Updated: 2024-08-04T22:40:16.048Z
Status : Modified
Published: 2019-10-24T16:15:20.047
Modified: 2024-11-21T04:20:22.730
Link: CVE-2019-11021
No data.
OpenCVE Enrichment
No data.
Weaknesses