CVE-2020-22249

CVE-2020-22249

Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file, Uploading a malicious plugin which contains the php files with extensions like PHP,phtml,php7 will be copied to the plugins directory which would lead to the remote code execution

Source: CVE-2020-22249

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다