SB2020090707 - Insecure handling of dangerous files in Concrete5
Published: September 7, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security restricitons bypass (CVE-ID: CVE-2020-24986)
The vulnerability allows a remote user to execute arbitrary PHP code.
The vulnerability exists due to application allows Concrete5 administrators to allow uploading of .php files to the server via File Manager. Once PHP files are allowed, a remote unprivileged user can upload and execute arbitrary PHP file on the system.
Remediation
Install update from vendor's website.