Security Advisory

CVE-2020-26678

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-05-26 11:50:40
Last updated 2024-08-04 15:56:05
Assigner mitre
State PUBLISHED

Description

vFairs 3.3 is affected by Remote Code Execution. Any user logged in to a vFairs virtual conference or event can abuse the functionality to upload a profile picture in order to place a malicious PHP file on the server and gain code execution.