Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

4N4Nd

#28291of 53,635
9Total CVSS
Vulnerabilities · 1
PT-2019-14924
9.0
2019-09-30
Ilch · Ilch · CVE-2019-17046
**Name of the Vulnerable Software and Affected Versions** Ilch version 2.1.22 **Description** The issue allows remote code execution. This is because `php` is listed under "Allowed files" on the `/admin/media/settings/index` page, which can be exploited. **Recommendations** For Ilch version 2.1.22, remove `php` from the list of "Allowed files" on the `/admin/media/settings/index` page to prevent remote code execution.