SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://github.com/siteserver/cms | third party advisory product |
https://github.com/siteserver/cms/issues/3236 | issue tracking third party advisory |
https://github.com/siteserver/cms/releases/download/siteserver-dev-v5.0.92/siteserver_install.zip | third party advisory patch |