CVE-2020-18432

CRITICAL

SEMCMS PHP 3.7 - Privilege Escalation

Title source: llm
STIX 2.1

Description

File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.

Scores

CVSS v3 9.8
EPSS 0.0067
EPSS Percentile 71.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
sem-cms/semcms 3.7
Published Jun 30, 2023
Tracked Since Feb 18, 2026