CVE-2020-21174: Malicious File Upload
Published Jun 20, 2023
·Updated
File Upload vulenrability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function.
Other sources
File Upload vulnerability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function.
Affected Software
2 affected componentsFixes available
composer/feehi/cms<2.0.8.1
2.0.8.1
Feehi Feehicms=2.0.7.1
Remediation
Patch Available
Event History
Jun 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
03:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-21174?
CVE-2020-21174 has a high severity due to its potential to allow remote code execution.
2
How do I fix CVE-2020-21174?
To fix CVE-2020-21174, upgrade to Feehi CMS version 2.0.8.1 or later.
3
What software is affected by CVE-2020-21174?
CVE-2020-21174 affects Feehi CMS version 2.0.7.1.
4
Can CVE-2020-21174 lead to data breaches?
Yes, CVE-2020-21174 can lead to data breaches by allowing attackers to execute arbitrary code.
5
Is CVE-2020-21174 exploit available?
While specific exploits are not publicly disclosed, the nature of CVE-2020-21174 makes it likely that attackers could develop an exploit.