Vulnerability Description
In Phproject before version 1.7.8, there's a vulnerability which allows users with access to file uploads to execute arbitrary code. This is patched in version 1.7.8.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phproject | Phproject | < 1.7.8 |
Related Weaknesses (CWE)
References
- https://github.com/Alanaktion/phproject/commit/b49d642e035d835f824bd39babd964ec0PatchThird Party Advisory
- https://github.com/Alanaktion/phproject/security/advisories/GHSA-4j97-6w6q-gxjxMitigationThird Party Advisory
- https://github.com/Alanaktion/phproject/commit/b49d642e035d835f824bd39babd964ec0PatchThird Party Advisory
- https://github.com/Alanaktion/phproject/security/advisories/GHSA-4j97-6w6q-gxjxMitigationThird Party Advisory
FAQ
What is CVE-2020-11011?
CVE-2020-11011 is a vulnerability with a CVSS score of 9.9 (CRITICAL). In Phproject before version 1.7.8, there's a vulnerability which allows users with access to file uploads to execute arbitrary code. This is patched in version 1.7.8.
How severe is CVE-2020-11011?
CVE-2020-11011 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-11011?
Check the references section above for vendor advisories and patch information. Affected products include: Phproject Phproject.