Back

HIGH

GXCMS V1.5 has a file upload vulnerability in the background

Published May 17, 2022

Description

GXCMS V1.5 has a file upload vulnerability in the background. The vulnerability is the template management page. You can edit any template content and then rename to PHP suffix file, after calling PHP file can control the server.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 17, 2022
Updated Aug 3, 2024
Reserved May 2, 2022
CISA Vulnrichment
Updated Jul 2, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a