CVE-2020-26048: Malicious File Upload
The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within an image extension and through a custom request using the rename function provided by the file manager is able to modify the image extension into PHP resulting in remote arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26048?
CVE-2020-26048 is considered to have a high severity due to the potential for remote code execution.
How do I fix CVE-2020-26048?
To fix CVE-2020-26048, upgrade your CuppaCMS installation to a version released after November 12, 2019.
What types of attacks can CVE-2020-26048 facilitate?
CVE-2020-26048 can facilitate remote file upload attacks, allowing an authenticated user to execute arbitrary PHP code.
Who is affected by CVE-2020-26048?
CVE-2020-26048 affects all versions of CuppaCMS prior to November 12, 2019.
Is authentication required to exploit CVE-2020-26048?
Yes, an attacker must be authenticated to exploit CVE-2020-26048 in the CuppaCMS file manager.