CVE-2020-36141: Malicious File Upload
BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Content-Type' header.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36141?
The severity of CVE-2020-36141 is high with a score of 8.8.
What is the vulnerability description of CVE-2020-36141?
CVE-2020-36141 is an Unrestricted File Upload vulnerability in BloofoxCMS 0.5.2.1 that allows bypassing MIME Type validation by inserting 'image/jpeg' within the 'Content-Type' header.
What software versions are affected by CVE-2020-36141?
BloofoxCMS versions 0.5.2.1 are affected by CVE-2020-36141.
How can the vulnerability be exploited?
The vulnerability in CVE-2020-36141 can be exploited by bypassing MIME Type validation and uploading files with a manipulated 'Content-Type' header.
Is there a fix for CVE-2020-36141?
At the moment, there is no known fix for CVE-2020-36141. It is recommended to update to a fixed version when available and apply any security patches provided by the vendor.