An issue was discovered in AContent through 1.4. It allows the user to run commands on the server with a low-privileged account. The upload section in the file manager page contains an arbitrary file upload vulnerability via upload.php. The extension .php7 bypasses file upload restrictions.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://sourceforge.net/projects/acontent/ | third party advisory |
https://github.com/cinzinga/CVEs/tree/master/CVE-2020-10557 | third party advisory exploit |