vendor:
CMSUno
by:
Fatih Çelik
9.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: CMSUno
Affected Version From: 1.6.2
Affected Version To: 1.6.2
Patch Exists: YES
Related CWE: N/A
CPE: a:boiteasite:cmsuno:1.6.2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux 2020.2
2020
CMSUno 1.6.2 – ‘user’ Remote Code Execution (Authenticated)
CMSUno 1.6.2 is vulnerable to authenticated remote code execution. An attacker can exploit this vulnerability by sending a malicious payload to the vulnerable URL. The payload will be executed on the server and a reverse shell will be established.
Mitigation:
Update CMSUno to the latest version and ensure that all users have strong passwords.