HIGH
Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with an zip extension, and then accessing it via unspecified vectors
Published Nov 10, 2016
7.2
HIGHCVSS 3.0
EPSS 5.00%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.