Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-101540
HistoryOct 12, 2021 - 12:00 a.m.

PHPFusion Arbitrary File Upload Vulnerability

2021-10-1200:00:00
China National Vulnerability Database
www.cnvd.org.cn
9

0.001 Low

EPSS

Percentile

43.2%

PHPFusion, a lightweight open source content management system, is vulnerable to arbitrary file uploads in PHPFusion version 9.03.110. The vulnerability stems from the fact that the File Manager feature in the administration panel does not filter PHP extensions. An attacker could exploit this vulnerability to upload malicious files and execute code on the server.

CPENameOperatorVersion
phpfusion phpfusioneq9.03.110

0.001 Low

EPSS

Percentile

43.2%

Related for CNVD-2021-101540