Security Advisory
CVE-2020-28062
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getList($decompath. / Upload/Plugins /, which could let a remote malicious user execute arbitrary code.