ZeroHour

CVE-2020-24036

PoC ×3
CVSS 3.1
8.8 high
EPSS
3%p86
Published
()
Modified
Description

PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code.

Vendors
fork-cms
Products
fork cms
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.