Security Advisory

CVE-2016-20052

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-04-04 13:50:57
Last updated 2026-04-06 15:28:54
Assigner VulnCheck
CVSS score 9.8
State PUBLISHED

Description

Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can upload malicious PHP files through the multipart form-data upload endpoint and execute them by accessing the uploaded file path to achieve remote code execution.