PT-2021-11001 · Fork Cms · Fork Cms

Published

2021-03-04

·

Updated

2021-07-21

·

CVE-2020-24036

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: ForkCMS versions prior to 5.8.3
Description: The issue allows an authenticated remote user to execute malicious code due to PHP object injection in the Ajax endpoint of the backend.
Recommendations: For versions prior to 5.8.3, update to version 5.8.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the Ajax endpoint in the backend until a patch is applied.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24036

Affected Products

Fork Cms