Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Tranqua

#28594of 53,624
9Total CVSS
Vulnerabilities · 1
PT-2021-22674
9.0
2021-08-23
Unknown · Flatcore-Cms · CVE-2021-39608
Name of the Vulnerable Software and Affected Versions: FlatCore-CMS version 2.0.7 Description: A Remote Code Execution (RCE) issue exists via the upload addon plugin, allowing a remote malicious user to execute arbitrary PHP code. Recommendations: For FlatCore-CMS version 2.0.7, consider disabling the upload addon plugin until a patch is available to prevent exploitation. Restrict access to the upload functionality to minimize the risk of arbitrary PHP code execution.