CVE-2020-36082: Malicious File Upload
Published Aug 11, 2023
·Updated
File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module.
Affected Software
1 affected component
bloofox bloofoxCMS=0.5.2.1
Event History
Aug 11, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2020-36082?
CVE-2020-36082 is a file upload vulnerability in bloofoxCMS version 0.5.2.1.
2
How does CVE-2020-36082 impact the system?
CVE-2020-36082 allows remote attackers to execute arbitrary code and escalate privileges through a crafted webshell file.
3
What is the severity of CVE-2020-36082?
CVE-2020-36082 has a severity rating of critical with a score of 9.8.
4
How can I fix CVE-2020-36082?
To fix CVE-2020-36082, it is recommended to update bloofoxCMS to version 0.5.2.2 or later.
5
Where can I find more information about CVE-2020-36082?
You can find more information about CVE-2020-36082 at the following link: [https://github.com/alexlang24/bloofoxCMS/issues/7](https://github.com/alexlang24/bloofoxCMS/issues/7).