vendor:
FlatCore CMS
by:
Mason Soroka-Gill
7.2
CVSS
HIGH
Remote Code Execution (RCE)
CWE
Product Name: FlatCore CMS
Affected Version From: 2.0.7
Affected Version To: 2.0.7
Patch Exists: NO
Related CWE: CVE-2021-39608
CPE: a:flatcore_cms:flatcore_cms:2.0.7
Platforms Tested: Ubuntu Server 21.04
2021
FlatCore CMS 2.0.7 – Remote Code Execution (RCE) (Authenticated)
This exploit allows an authenticated attacker to execute arbitrary code on a target system running FlatCore CMS version 2.0.7. The vulnerability exists in the 'files.upload-script.php' script, which allows an attacker to upload a malicious PHP file and execute arbitrary commands through the 'sg' parameter in the URL.
Mitigation:
Update to a patched version of FlatCore CMS.