Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-19510
Reference (s):
- http://blog.topsec.com.cn/textpattern-background-any-file-upload/

