PT-2024-10785 · Codoforum · Codoforum

·

CVE-2020-22539

·

Published

2024-04-15

·

Updated

2024-08-22

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Codoforum version 4.9
Description An arbitrary file upload vulnerability in the Add Category function allows attackers to execute arbitrary code via uploading a crafted file.
Recommendations For Codoforum version 4.9, consider disabling the Add Category function until a patch is available to prevent exploitation. Restrict access to file upload features to minimize the risk of arbitrary code execution.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-22539

Affected Products

Codoforum