Security Advisory

CVE-2020-28062

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-04-04 16:36:44
Last updated 2024-08-04 16:33:56
Assigner mitre
State PUBLISHED

Description

An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getList($decompath. / Upload/Plugins /, which could let a remote malicious user execute arbitrary code.