Permissions vulnerability in Fuel-CMS v.1.4.6 allows a...
Critical severity
Unreviewed
Published
Jul 3, 2023
to the GitHub Advisory Database
•
Updated Nov 25, 2024
Description
Published by the National Vulnerability Database
Jul 3, 2023
Published to the GitHub Advisory Database
Jul 3, 2023
Last updated
Nov 25, 2024
Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests parameter of the upload function.
References