flatCore before 1.5.7 allows upload and execution of a .php file by an admin.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://lists.openwall.net/full-disclosure/2020/08/07/1 | mailing list exploit third party advisory |
https://sec-consult.com/en/blog/advisories/multiple-vulnerabilities-in-flatcore-cms/ | third party advisory exploit |