ZeroHour

CVE-2020-25538

PoC ×2
CVSS 3.1
8.8 high
EPSS
10%p95
Published
()
Modified
Description

An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web page. In this way, attacker can takeover the control of the server.

Vendors
cmsuno project
Products
cmsuno
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.