CVEs Blog | G5 Cyber Security

CVE-2020-24036 – PHP object injection in the Ajax endpoint of the backend in ForkCMS below

PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24036

Reference (s):

Exit mobile version