Vulnerability Description
FeiFeiCMS 4.1.190209 allows remote attackers to upload and execute arbitrary PHP code by visiting index.php?s=Admin-Index to modify the set of allowable file extensions, as demonstrated by adding php to the default jpg,gif,png,jpeg setting, and then using the "add article" feature.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Feifeicms | Feifeicms | 4.1.190209 |
Related Weaknesses (CWE)
References
- http://blog.whiterabbitxyj.com/cve/FeiFeiCMS_4.1_code_execution.docThird Party Advisory
- https://github.com/WhiteRabbitc/WhiteRabbitc.github.io/blob/master/cve/FeiFeiCMSThird Party Advisory
- http://blog.whiterabbitxyj.com/cve/FeiFeiCMS_4.1_code_execution.docThird Party Advisory
- https://github.com/WhiteRabbitc/WhiteRabbitc.github.io/blob/master/cve/FeiFeiCMSThird Party Advisory
FAQ
What is CVE-2019-9825?
CVE-2019-9825 is a vulnerability with a CVSS score of 9.8 (CRITICAL). FeiFeiCMS 4.1.190209 allows remote attackers to upload and execute arbitrary PHP code by visiting index.php?s=Admin-Index to modify the set of allowable file extensions, as demonstrated by adding php ...
How severe is CVE-2019-9825?
CVE-2019-9825 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-9825?
Check the references section above for vendor advisories and patch information. Affected products include: Feifeicms Feifeicms.