CVE-2020-22643

HIGH7.2EPSS 2.1%

Feehi CMS arbitrary file upload vulnerability

Published: 5/24/2022Modified: 2/16/2024
Also known as:GHSA-65x8-9vgm-5fg5

Description

Feehi CMS 2.1.0-beta is affected by an arbitrary file upload vulnerability, potentially resulting in remote code execution. After an administrator logs in, open the administrator image upload page to potentially upload malicious files.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References (3)