PT-2021-10774 · Feehicms · Feehicms

Whb5974

·

Published

2021-01-21

·

Updated

2022-05-24

·

CVE-2020-22643

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Feehi CMS versions 2.1.0 through 2.1.0
Description The issue allows for an arbitrary file upload, potentially resulting in remote code execution. This can be achieved by accessing the administrator image upload page after an administrator has logged in, allowing for the potential upload of malicious files.
Recommendations For Feehi CMS version 2.1.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-22643
GHSA-65X8-9VGM-5FG5

Affected Products

Feehicms