CVE-2020-5640

Unauthenticated LFI to RCE in OneThird CMS

OneThird CMS におけるローカルファイルインクルージョン

Local file inclusion vulnerability in OneThird CMS v1.96c and earlier allows a remote unauthenticated attacker to execute arbitrary code via undisclosed file upload feature. The attacker can also use this vulnerability to obtain arbitrary files and sensitive information such as database.

Disclosure Date

2020/10/20

Credit

stypr (@stereotype32)

CWE

  • CWE-98

Product URLs

Reference