CVE-2020-35760: Malicious File Upload
Published Jun 16, 2021
·Updated
bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files).
Affected Software
1 affected component
bloofox bloofoxCMS=0.5.2.1
Event History
Jun 16, 2021
CVE Published
via MITRE·03:52 PM
Data Sourced
via MITRE·03:52 PM
Description
Frequently Asked Questions
1
What is CVE-2020-35760?
CVE-2020-35760 is a vulnerability in bloofoxCMS 0.5.2.1 that allows attackers to upload malicious files through unrestricted file upload.
2
How severe is the CVE-2020-35760 vulnerability?
The severity of the CVE-2020-35760 vulnerability is rated as critical with a severity score of 9.8.
3
What is the affected software version for CVE-2020-35760?
The affected software version for CVE-2020-35760 is bloofoxCMS 0.5.2.1.
4
How can attackers exploit CVE-2020-35760?
Attackers can exploit CVE-2020-35760 by uploading malicious files, such as PHP files, through the unrestricted file upload feature.
5
Is there a fix for CVE-2020-35760?
Yes, the fix for CVE-2020-35760 is to update bloofoxCMS to a version that patches the unrestricted file upload vulnerability.