PT-2022-8641 · Feehicms · Feehicms

Tatsumaki002

·

Published

2022-09-06

·

Updated

2022-09-09

·

CVE-2020-21516

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FeehiCMS versions 2.0.8 through 2.0.8.1
Description The issue is related to an arbitrary file upload vulnerability at the head image upload, allowing attackers to execute relevant PHP code.
Recommendations For FeehiCMS version 2.0.8, update to a version that fixes the arbitrary file upload vulnerability. For FeehiCMS version 2.0.8.1, update to a version that fixes the arbitrary file upload vulnerability.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2020-21516
GHSA-JJ62-MC3M-J769

Affected Products

Feehicms