CVE-2020-14067

CVE-2020-14067

The install_from_hash functionality in Navigate CMS 2.9 does not consider the .phtml extension when examining files within a ZIP archive that may contain PHP code, in check_upload in lib/packages/extensions/extension.class.php and lib/packages/themes/theme.class.php.

Source: CVE-2020-14067

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다