Security Advisory

CVE-2020-25042

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-09-03 14:23:13
Last updated 2024-08-04 15:26:09
Assigner mitre
State PUBLISHED

Description

An arbitrary file upload issue exists in Mara CMS 7.5. In order to exploit this, an attacker must have a valid authenticated (admin/manager) session and make a codebase/dir.php?type=filenew request to upload PHP code to codebase/handler.php.