CVE-2020-36037: High severity wuzhi cms vulnerability
Published Aug 11, 2023
·Updated
An issue was disocvered in wuzhicms version 4.1.0, allows remote attackers to execte arbitrary code via the setting parameter to the ueditor in index.php.
Affected Software
1 affected component
Wuzhicms Wuzhicms=4.1.0
Event History
Aug 11, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2020-36037?
CVE-2020-36037 is a vulnerability in Wuzhicms version 4.1.0 that allows remote attackers to execute arbitrary code.
2
How does CVE-2020-36037 affect Wuzhicms?
CVE-2020-36037 affects Wuzhicms version 4.1.0.
3
How can an attacker exploit CVE-2020-36037?
An attacker can exploit CVE-2020-36037 by sending a specially crafted setting parameter to the ueditor in index.php.
4
What is the severity of CVE-2020-36037?
CVE-2020-36037 has a severity of 8.8 out of 10.
5
Is there a fix for CVE-2020-36037?
As of now, there is no official fix available for CVE-2020-36037. It is recommended to update to a fixed version when one becomes available.