PT-2021-11927 · Unknown · Bloofoxcms

CVE-2020-36141

·

Published

2021-06-04

·

Updated

2024-02-14

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: BloofoxCMS version 0.5.2.1
Description: The issue allows for Unrestricted File Upload by bypassing MIME Type validation. This can be achieved by inserting 'image/jpeg' within the 'Content-Type' header, potentially allowing malicious files to be uploaded to the system.
Recommendations: For BloofoxCMS version 0.5.2.1, consider validating the MIME Type of uploaded files more rigorously to prevent bypassing of the validation mechanism. As a temporary workaround, restrict the types of files that can be uploaded to mitigate the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36141

Affected Products

Bloofoxcms