PT-2026-5465 · Koken Cms · Koken Cms
V1N1V131R4
·
Publicado
2026-01-30
·
Atualizado
2026-01-30
·
CVE-2020-37023
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Koken CMS version 0.22.24
Description
Koken CMS contains a file upload issue that permits authenticated attackers to circumvent file extension limitations by renaming malicious PHP files. Attackers can upload PHP files capable of executing system commands by altering the file upload request using a web proxy and modifying the file extension. The issue allows bypassing file extension restrictions.
Recommendations
Update to a newer version that contains a fix for this vulnerability.
Exploit
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Koken Cms