PT-2020-3997 · Acymailing · Acymailing
Published
2020-03-24
·
Updated
2023-02-03
·
CVE-2020-10934
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
AcyMailing versions prior to 6.9.2
Description:
The issue is related to the lack of restrictions on file uploads in the AcyMailing mail manager. This can be exploited by a remote attacker to execute arbitrary code. The problem arises from the mishandling of file uploads by administrators.
Recommendations:
For versions prior to 6.9.2, update to version 6.9.2 or later to resolve the issue. As a temporary workaround, consider restricting file upload capabilities for administrators until the update is applied.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acymailing