CVE-2020-25287: Malicious File Upload
Pligg 2.0.3 allows remote authenticated users to execute arbitrary commands because the template editor can edit any file, as demonstrated by an admin/admineditor.php thefile=..%2Findex.php&open=Open request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25287?
CVE-2020-25287 is considered a critical severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2020-25287?
To fix CVE-2020-25287, upgrade to a patched version of Pligg CMS that addresses the vulnerability.
What impact does CVE-2020-25287 have on my system?
CVE-2020-25287 allows authenticated users to execute arbitrary commands, which can compromise the security of your system.
Who is affected by CVE-2020-25287?
CVE-2020-25287 affects users of Pligg CMS version 2.0.3 who have access to the template editor.
Is there a workaround for CVE-2020-25287?
A possible workaround for CVE-2020-25287 is to restrict access to the template editor for non-administrative users.