First published: Wed Feb 17 2021(Updated: )
In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /ThinkPHP/Common/functions.php where attackers can obtain server permissions and control the server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ditcms | =5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35339 is a remote code execution vulnerability in 74cms version 5.0.1.
CVE-2020-35339 has a severity rating of critical with a score of 9.8.
74cms version 5.0.1 is affected by CVE-2020-35339.
Attackers can exploit CVE-2020-35339 by accessing /Application/Admin/Controller/ConfigController.class.php and /ThinkPHP/Common/functions.php to gain server permissions and control the server.
You can find more information about CVE-2020-35339 on the official 74cms website and the GitHub repository provided in the references.