PT-2021-10745 · Phpcms · Phpcms

Blindkey

·

Published

2021-06-16

·

Updated

2022-09-29

·

CVE-2020-22201

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions phpCMS 2008 sp4
Description The issue allows remote malicious users to execute arbitrary php commands. This is achieved via the pagesize parameter to the "yp/product.php" endpoint.
Recommendations For phpCMS 2008 sp4, consider restricting access to the "yp/product.php" endpoint or avoid using the pagesize parameter until a fix is available.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2020-22201

Affected Products

Phpcms