CVE-2020-26670

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
01/06/2021
Last modified:
03/05/2022

Description

A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary commands through a crafted request sent to the server via the 'Create a New Setting' function.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bigtreecms:bigtree_cms:*:*:*:*:*:*:*:* 4.4.10 (including)


References to Advisories, Solutions, and Tools