PT-2020-16481 · Atomx · Atomcms
R4Ilgun
·
Published
2020-10-22
·
Updated
2021-07-21
·
CVE-2020-26649
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AtomXCMS version 2.0
Description
The issue is related to Incorrect Access Control, which can be exploited via the "admin/dump.php" endpoint.
Recommendations
For AtomXCMS version 2.0, consider restricting access to the
admin/dump.php endpoint until a fix is available.Exploit
Fix
Missing Authorization
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Atomcms