CVE-2020-21005

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
03/06/2021
Last modified:
11/06/2021

Description

WellCMS 2.0 beta3 is vulnerable to File Upload. A user can log in to the CMS background and upload a picture. Because the upload file type is controllable, the user can modify the upload file type to get webshell.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wellcms:wellcms:2.0:beta3:*:*:*:*:*:*