Arbitrary file upload in Gila CMS - CVE-2019-17536
Published: December 5, 2019
Gila CMS
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file extension within the moveAction() function in core/controllers/fm.php. A remote attacker can upload a malicious file via the admin/media_upload and fm/move and execute arbitrary file on the server.