CVE-2020-25538

An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web page. In this way, attacker can takeover the control of the server.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:cmsuno_project:cmsuno:1.6.2:*:*:*:*:*:*:*

Information

Published : 2020-11-13 08:15

Updated : 2021-07-21 04:39


NVD link : CVE-2020-25538

Mitre link : CVE-2020-25538


JSON object : View

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

Advertisement

dedicated server usa

Products Affected

cmsuno_project

  • cmsuno