Lucene search

K
osvGoogleOSV:CVE-2020-22249
HistoryJul 06, 2021 - 8:15 p.m.

CVE-2020-22249

2021-07-0620:15:07
Google
osv.dev
6
remote code exec
phplist
vulnerability
file extensions
malicious plugins

AI Score

8.2

Confidence

Low

EPSS

0.011

Percentile

84.1%

Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file, Uploading a malicious plugin which contains the php files with extensions like PHP,phtml,php7 will be copied to the plugins directory which would lead to the remote code execution

AI Score

8.2

Confidence

Low

EPSS

0.011

Percentile

84.1%

Related for OSV:CVE-2020-22249