CVE-2020-20691

An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploading crafted HTML files.
References
Link Resource
https://github.com/monstra-cms/monstra/issues/461 Exploit Issue Tracking Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:monstra:monstra_cms:3.0.4:*:*:*:*:*:*:*

Information

Published : 2021-09-27 15:15

Updated : 2021-10-08 07:58


NVD link : CVE-2020-20691

Mitre link : CVE-2020-20691


JSON object : View

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type

Advertisement

dedicated server usa

Products Affected

monstra

  • monstra_cms