An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary code via a crafted PHP file.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://github.com/xxhzz1/74cmsSE-Arbitrary-file-upload-vulnerability/issues/1 | issue tracking exploit third party advisory |