CVEs Blog | G5 Cyber Security

CVE-2020-14067 – The install_from_hash functionality in Navigate CMS 2.9 does not consider

The install_from_hash functionality in Navigate CMS 2.9 does not consider the .phtml extension when examining files within a ZIP archive that may contain PHP code, in check_upload in lib/packages/extensions/extension.class.php and lib/packages/themes/theme.class.php.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14067

Reference (s):

Exit mobile version