CVE-2020-11011: RCE via file upload in Phproject
Published Apr 22, 2020
·Updated
In Phproject before version 1.7.8, there's a vulnerability which allows users with access to file uploads to execute arbitrary code. This is patched in version 1.7.8.
Affected Software
1 affected component
Phproject Phproject<1.7.8
Remediation
Event History
Apr 22, 2020
CVE Published
via MITRE·04:15 PM
Data Sourced
via MITRE·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-11011?
CVE-2020-11011 is classified as a high severity vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2020-11011?
To fix CVE-2020-11011, upgrade to Phproject version 1.7.8 or later.
3
Who is affected by CVE-2020-11011?
Users of Phproject prior to version 1.7.8 who have access to file uploads are affected by CVE-2020-11011.
4
What type of vulnerability is CVE-2020-11011?
CVE-2020-11011 is an arbitrary code execution vulnerability associated with file upload functionality.
5
Can CVE-2020-11011 be exploited remotely?
Yes, CVE-2020-11011 can potentially be exploited remotely if an attacker can upload malicious files.