ZeroHour

CVE-2020-36082

PoC
CVSS 3.1
9.8 critical
EPSS
1%p66
Published
()
Modified
Description

File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module.

Vendors
bloofox
Products
bloofoxcms
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.