Security Advisory

CVE-2020-24986

7.2
HIGH

Vulnerability Description

Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File Manager. It is possible to modify site configuration to upload the PHP file and execute arbitrary commands.
Published Date September 4, 2020
Official Source NIST NVD Advisory