CVE-2020-25790

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
19/09/2020
Last modified:
04/08/2024

Description

Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes the significance of this report because "admins are considered trustworthy"; however, the behavior "contradicts our security policy" and is being fixed for 5.2

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:typesettercms:typesetter:*:*:*:*:*:*:*:* 5.0 (including) 5.1 (including)