CVE-2020-22153: Malicious File Upload
Published Jul 3, 2023
·Updated
File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in the navigation function.
Affected Software
1 affected component
TheDayLightStudio Fuel CMS=1.4.6
Event History
Jul 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-22153?
The severity of CVE-2020-22153 is critical with a score of 9.8.
2
How does CVE-2020-22153 affect FUEL-CMS?
CVE-2020-22153 affects FUEL-CMS version 1.4.6.
3
What is the vulnerability in CVE-2020-22153?
CVE-2020-22153 is a file upload vulnerability that allows a remote attacker to execute arbitrary code.
4
How can an attacker exploit CVE-2020-22153?
An attacker can exploit CVE-2020-22153 by uploading a crafted .php file to the upload parameter in the navigation function.
5
Is there a fix for CVE-2020-22153?
A fix for CVE-2020-22153 is not available at this time. It is recommended to update to a newer version of FUEL-CMS.