PT-2026-30350 · Undefined · Undefined

Published

2026-04-04

·

Updated

2026-04-04

·

CVE-2016-20052

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews files directory. Attackers can upload malicious PHP files through the multipart form-data upload endpoint and execute them by accessing the uploaded file path to achieve remote code execution.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2016-20052

Affected Products

Undefined