First published: Sat Mar 30 2019(Updated: )
An issue was discovered in flatCore 1.4.7. acp/acp.php allows remote authenticated administrators to upload arbitrary .php files, related to the addons feature.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Flatcore Flatcore | =1.4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-10652 is high, with a CVSS score of 7.2.
Flatcore version 1.4.7 is affected by CVE-2019-10652.
Remote authenticated administrators can exploit CVE-2019-10652 by uploading arbitrary .php files using the addons feature in flatCore version 1.4.7.
Yes, a fix for CVE-2019-10652 is available. It is recommended to update to a patched version of flatCore CMS.
More information about CVE-2019-10652 can be found at the following reference: [https://github.com/flatCore/flatCore-CMS/issues/38]