CVE-2020-25557
CVE-2020-25557
In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs in to the application, attacker's code will be run. As a result of this vulnerability, authenticated user can run command on the server.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencepacketstormsecurity.com/files/161162/CMSUno-1.6.2-Remote-Code-Execution.htmlunverifiedexploitdbwww.exploit-db.com/exploits/49485unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →