PT-2020-15565 · Imcat · Imcat
Published
2020-12-09
·
Updated
2020-12-10
·
CVE-2020-23520
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
imcat version 5.2
Description
The issue allows an authenticated file upload and consequently remote code execution via the picture functionality.
Recommendations
For imcat version 5.2, consider disabling the picture functionality until a patch is available to prevent remote code execution. Restrict access to file upload features to minimize the risk of exploitation.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Imcat