Vulnerability Description
In Sentrifugo 3.2, users can upload an image under "Assets -> Add" tab. This "Upload Images" functionality is suffered from "Unrestricted File Upload" vulnerability so attacker can upload malicious files using this functionality and control the server.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sapplica | Sentrifugo | 3.2 |
Related Weaknesses (CWE)
References
- https://fatihhcelik.blogspot.com/2020/10/sentrifugo-version-32-rce-authenticatedExploitThird Party Advisory
- https://fatihhcelik.blogspot.com/2020/10/sentrifugo-version-32-rce-authenticatedExploitThird Party Advisory
FAQ
What is CVE-2020-26803?
CVE-2020-26803 is a vulnerability with a CVSS score of 8.8 (HIGH). In Sentrifugo 3.2, users can upload an image under "Assets -> Add" tab. This "Upload Images" functionality is suffered from "Unrestricted File Upload" vulnerability so attacker can upload malicious fi...
How severe is CVE-2020-26803?
CVE-2020-26803 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-26803?
Check the references section above for vendor advisories and patch information. Affected products include: Sapplica Sentrifugo.