The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within an image extension and through a custom request using the rename function provided by the file manager is able to modify the image extension into PHP resulting in remote arbitrary code execution.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-18678 The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within an image extension and through a custom request using the rename function provided by the file manager is able to modify the image extension into PHP resulting in remote arbitrary code execution.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T15:49:06.753Z

Reserved: 2020-09-24T00:00:00

Link: CVE-2020-26048

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-10-05T15:15:12.170

Modified: 2024-11-21T05:19:06.003

Link: CVE-2020-26048

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.