PT-2021-10536 · S-Cms Php · S-Cms Php

Published

2021-07-27

·

Updated

2021-08-05

·

CVE-2020-20698

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: S-CMS PHP version 3.0
Description: A remote code execution issue in the /1.com.php file of S-CMS PHP allows attackers to execute arbitrary code via modification of a PHP file, potentially leading to unauthorized access. The issue can be exploited by modifying a PHP file, which enables attackers to getshell.
Recommendations: For S-CMS PHP version 3.0, update the /1.com.php file to prevent modification by unauthorized users. As a temporary workaround, consider restricting access to the /1.com.php file until a patch is available.

Exploit

Fix

RCE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-20698

Affected Products

S-Cms Php