RiteCMS version 3.1.0 and below suffers from a remote...
High severity
Unreviewed
Published
Apr 9, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Apr 8, 2022
Published to the GitHub Advisory Database
Apr 9, 2022
Last updated
Jan 27, 2023
RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated attacker can upload a PHP file and bypass the .htacess configuration to deny execution of .php files in media and files directory by default.
References