CVE-2020-19551: High severity wuzhi cms vulnerability
Published Sep 21, 2021
·Updated
Blacklist bypass issue exists in WUZHI CMS up to and including 4.1.0 in common.func.php, which when uploaded can cause remote code executiong.
Affected Software
1 affected component
Wuzhicms Wuzhicms<=4.1.0
Event History
Sep 21, 2021
CVE Published
via MITRE·06:31 PM
Data Sourced
via MITRE·06:31 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2020-19551.
2
What is the affected software and version?
The affected software is Wuzhicms Wuzhicms up to and including version 4.1.0.
3
What is the severity of CVE-2020-19551?
The severity of CVE-2020-19551 is high with a CVSS score of 8.8.
4
What is the description of CVE-2020-19551?
CVE-2020-19551 is a blacklist bypass issue in Wuzhicms Wuzhicms up to and including version 4.1.0, which can cause remote code execution when a certain file is uploaded.
5
Is there any fix available for this vulnerability?
Yes, there is currently no known fix for CVE-2020-19551. It is recommended to update to a version that is not affected.