Hongcms · Hongcms · CVE-2020-21431
Name of the Vulnerable Software and Affected Versions:
HongCMS version 3.0
Description:
The issue concerns an arbitrary file read and write vulnerability. It is located in the component `/admin/index.php/template/edit`.
Recommendations:
For HongCMS version 3.0, consider restricting access to the `/admin/index.php/template/edit` component until a fix is available. As a temporary workaround, limit the functionality of the edit template feature to minimize the risk of exploitation.