PT-2021-11927 · Unknown · Bloofoxcms

Published

2021-06-04

·

Updated

2024-02-14

·

CVE-2020-36141

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: BloofoxCMS version 0.5.2.1
Description: The issue allows for Unrestricted File Upload by bypassing MIME Type validation. This can be achieved by inserting 'image/jpeg' within the 'Content-Type' header, potentially allowing malicious files to be uploaded to the system.
Recommendations: For BloofoxCMS version 0.5.2.1, consider validating the MIME Type of uploaded files more rigorously to prevent bypassing of the validation mechanism. As a temporary workaround, restrict the types of files that can be uploaded to mitigate the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2020-36141

Affected Products

Bloofoxcms