Lucene search

K
cvelistMitreCVELIST:CVE-2020-22249
HistoryJul 06, 2021 - 7:47 p.m.

CVE-2020-22249

2021-07-0619:47:39
mitre
www.cve.org
vulnerability
phplist
remote code execution
plugin
file extensions
malicious
php files
directory
uploading

AI Score

10

Confidence

High

EPSS

0.011

Percentile

84.1%

Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file, Uploading a malicious plugin which contains the php files with extensions like PHP,phtml,php7 will be copied to the plugins directory which would lead to the remote code execution

AI Score

10

Confidence

High

EPSS

0.011

Percentile

84.1%

Related for CVELIST:CVE-2020-22249