CVE-2008-6951

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
12/08/2009
Last modified:
09/04/2025

Description

MauryCMS 0.53.2 and earlier does not require administrative authentication for Editors/fckeditor/editor/filemanager/browser/default/browser.html, which allows remote attackers to upload arbitrary files via a direct request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cms.maury91:maurycms:0.53.2:*:*:*:*:*:*:*