File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type to image/jpeg and placing PHP code after the JPEG data, which could let a remote malicious user execute arbitrary PHP code.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-20092
Reference (s):
- https://github.com/woider/ArticleCMS/issues/8

