Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-64046
HistoryAug 15, 2023 - 12:00 a.m.

bloofoxCMS File Upload Vulnerability (CNVD-2023-64046)

2023-08-1500:00:00
China National Vulnerability Database
www.cnvd.org.cn
6
bloofoxcms
vulnerability
file upload
arbitrary code
webshell
privilege escalation
security issue

EPSS

0.004

Percentile

72.3%

bloofoxCMS is Bloofox (bloofoxCMS) individual developers of a Php-based text content management system. A file upload vulnerability exists in bloofoxCMS version 0.5.2.1, which stems from the application’s lack of valid validation of uploaded files. The vulnerability can be exploited to execute arbitrary code and escalate privileges via a well-designed webshell file upload module.

EPSS

0.004

Percentile

72.3%

Related for CNVD-2023-64046