CVE-2020-10228
HIGHvtenext 19 CE - Authenticated Remote Code Execution via .pht File Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-10228. PoCs published by Marco Ruela.
AI-analyzed exploit summary This exploit chains XSS, file upload, and CSRF vulnerabilities in VTENEXT 19 CE to achieve remote code execution. It sends a malicious email with an XSS payload that triggers a file upload of a PHP shell, then locates and executes commands on the uploaded shell.
Description
A file upload vulnerability in vtecrm vtenext 19 CE allows authenticated users to upload files with a .pht extension, resulting in remote code execution.
Exploits (1)
This exploit chains XSS, file upload, and CSRF vulnerabilities in VTENEXT 19 CE to achieve remote code execution. It sends a malicious email with an XSS payload that triggers a file upload of a PHP shell, then locates and executes commands on the uploaded shell.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H