In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs in to the application, attacker's code will be run. As a result of this vulnerability, authenticated user can run command on the server.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-11-13T15:25:13
Updated: 2024-08-04T15:33:05.689Z
Reserved: 2020-09-14T00:00:00
Link: CVE-2020-25557
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-11-13T16:15:18.197
Modified: 2024-11-21T05:18:06.203
Link: CVE-2020-25557
Redhat
No data.