Unknown · Flatcore-Cms · CVE-2021-39608
Name of the Vulnerable Software and Affected Versions:
FlatCore-CMS version 2.0.7
Description:
A Remote Code Execution (RCE) issue exists via the upload addon plugin, allowing a remote malicious user to execute arbitrary PHP code.
Recommendations:
For FlatCore-CMS version 2.0.7, consider disabling the upload addon plugin until a patch is available to prevent exploitation. Restrict access to the upload functionality to minimize the risk of arbitrary PHP code execution.