PT-2023-11534 · Unknown · Cskaza Csz Cms

Published

2023-03-23

·

Updated

2023-03-30

·

CVE-2020-19786

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CSKaza CSZ CMS versions 1.2.2 through 1.2.3
Description The issue allows an attacker to execute arbitrary commands and code via a crafted PHP file, exploiting a file upload vulnerability.
Recommendations For CSKaza CSZ CMS versions 1.2.2 through 1.2.3, update to version 1.2.4 to resolve the issue.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-19786

Affected Products

Cskaza Csz Cms