Security Advisory
CVE-2020-24986
7.2
HIGH
Vulnerability Description
Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File Manager. It is possible to modify site configuration to upload the PHP file and execute arbitrary commands.
Published Date
September 4, 2020
Official Source
NIST NVD Advisory