vendor:
Croogo
by:
Deha Berkin Bir
7.5
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: Croogo
Affected Version From: 3.0.2
Affected Version To: 3.0.2
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 Home Single Language 20H2 & WampServer 3.2.3
2021
Croogo 3.0.2 – Remote Code Execution (Authenticated)
This exploit allows an authenticated user to upload a malicious PHP script and execute arbitrary code on the server. The vulnerability exists in Croogo version 3.0.2.
Mitigation:
Update to a patched version of Croogo or apply the vendor's recommended security measures.