Feehi CMS arbitrary file upload vulnerability
High severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jul 7, 2023
Description
Published by the National Vulnerability Database
Jan 26, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jul 7, 2023
Reviewed
Jul 7, 2023
Feehi CMS 2.1.0-beta is affected by an arbitrary file upload vulnerability, potentially resulting in remote code execution. After an administrator logs in, open the administrator image upload page to potentially upload malicious files.
References