PT-2026-3156 · Phpcms · Phpcms
Okan Kurtulus
·
Publicado
2026-01-15
·
Atualizado
2026-02-09
·
CVE-2021-47783
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Phpwcms version 1.9.30
Description
The software contains a file upload issue that permits authenticated attackers to upload malicious SVG files containing JavaScript. Attackers can leverage the multiple file upload functionality to upload specially crafted SVG payloads, potentially leading to cross-site scripting attacks on the platform. The vulnerable functionality involves the upload of files.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Phpcms