PT-2026-5465 · Koken Cms · Koken Cms
V1N1V131R4
·
Published
2026-01-30
·
Updated
2026-01-30
·
CVE-2020-37023
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Koken CMS version 0.22.24
Description
Koken CMS contains a file upload issue that permits authenticated attackers to circumvent file extension limitations by renaming malicious PHP files. Attackers can upload PHP files capable of executing system commands by altering the file upload request using a web proxy and modifying the file extension. The issue allows bypassing file extension restrictions.
Recommendations
Update to a newer version that contains a fix for this vulnerability.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Koken Cms