CVE-2020-28693

Publication date

2020-11-16 20:42:22

Family

mitre

State

PUBLISHED

Description

An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code through a zip file by uploading a theme, and executing the PHP file via an HTTP GET request to /themes/