CVE-2020-21359

Published

Severity

CVSS v3:
9.8 CRITICAL
CVSS v2:
7.5 HIGH

Description

An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execute arbitrary code via adding a character to the end of the uploaded file's name.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:maccms:maccms:10.0:*:*:*:*:*:*:*n/an/a10.0

External Links