CVE-2022-24652

Publication date

2022-03-10 17:31:46

Family

mitre

State

PUBLISHED

Description

sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in php code execution in /admin/upload/upload.