PT-2019-6067 · Aik · Aikcms

Richard1266

·

Published

2019-04-29

·

Updated

2021-08-17

·

CVE-2020-18462

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions AikCms version 2.0.0
Description The issue is related to a lack of restrictions on file uploads in the poster edit.php file of the AikCms content management system. This can be exploited by a remote attacker to impact the confidentiality, integrity, and availability of protected information. The vulnerability is due to the background file management office not verifying the uploaded files.
Recommendations For AikCms version 2.0.0, consider restricting access to the poster edit.php file until a patch is available, and ensure that all file uploads are properly verified to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04473
CVE-2020-18462

Affected Products

Aikcms