PT-2021-17118 · Unknown · Millken Doyocms

Jayus0821

·

Published

2021-11-01

·

Updated

2021-11-02

·

CVE-2021-26740

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions millken doyocms version 2.3
Description The issue allows attackers to execute arbitrary code due to an arbitrary file upload vulnerability in the sysupload.php file.
Recommendations For millken doyocms version 2.3, consider disabling the sysupload.php file until a patch is available to prevent arbitrary file uploads and subsequent code execution.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-26740

Affected Products

Millken Doyocms