Arbitrary file upload in HongCMS - CVE-2018-13021
Published: July 2, 2018 / Updated: October 21, 2019
HongCMS
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to the application allows unrestricted upload of dangerous files in "admin/index.php/template/upload" URI. A remote authenticated user can upload a malicious PHP script on the server and execute it.