First published: Wed Dec 02 2020(Updated: )
PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 allows remote code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ditcms | <6.0.48 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-29279.
The severity of CVE-2020-29279 is critical with a CVSS score of 9.8.
The versions affected by CVE-2020-29279 are up to version 6.0.48 of 74CMS.
CVE-2020-29279 allows remote code execution through PHP remote file inclusion in the assign_resume_tpl method in ApplicationController/BaseController.class.php in 74CMS before version 6.0.48.
To fix CVE-2020-29279, update 74CMS to a version above 6.0.48 and ensure that remote file inclusion vulnerabilities are properly mitigated.