Vulnerability Description
Feehi CMS 2.1.0 is affected by an arbitrary file upload vulnerability, potentially resulting in remote code execution. After an administrator logs in, open the administrator image upload page to potentially upload malicious files.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Feehi | Feehi Cms | 2.1.0 |
Related Weaknesses (CWE)
References
- https://github.com/liufee/cms/issues/51ExploitIssue TrackingThird Party Advisory
- https://github.com/liufee/cms/issues/51ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2020-22643?
CVE-2020-22643 is a vulnerability with a CVSS score of 7.2 (HIGH). Feehi CMS 2.1.0 is affected by an arbitrary file upload vulnerability, potentially resulting in remote code execution. After an administrator logs in, open the administrator image upload page to poten...
How severe is CVE-2020-22643?
CVE-2020-22643 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-22643?
Check the references section above for vendor advisories and patch information. Affected products include: Feehi Feehi Cms.