ZeroHour

CVE-2020-20287

PoC
CVSS 3.1
9.8 critical
EPSS
3%p86
Published
()
Modified
Description

Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request parameters, triggers remote code execution.

Vendors
yccms
Products
yccms
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.