First published: Fri Aug 11 2023(Updated: )
File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bloofox Bloofoxcms | =0.5.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-36082 is a file upload vulnerability in bloofoxCMS version 0.5.2.1.
CVE-2020-36082 allows remote attackers to execute arbitrary code and escalate privileges through a crafted webshell file.
CVE-2020-36082 has a severity rating of critical with a score of 9.8.
To fix CVE-2020-36082, it is recommended to update bloofoxCMS to version 0.5.2.2 or later.
You can find more information about CVE-2020-36082 at the following link: [https://github.com/alexlang24/bloofoxCMS/issues/7](https://github.com/alexlang24/bloofoxCMS/issues/7).