PT-2021-17135 · Unknown · Frogcms Sentcms

L1Nk3R

·

Published

2021-09-23

·

Updated

2021-09-29

·

CVE-2021-26794

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FrogCMS SentCMS version 0.9.5
Description The issue allows for privilege escalation in the 'upload.php' file, enabling an attacker to execute arbitrary code by uploading a crafted php file.
Recommendations For FrogCMS SentCMS version 0.9.5, consider disabling the 'upload.php' file or restricting its access until a patch is available to prevent arbitrary code execution.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-26794

Affected Products

Frogcms Sentcms