CVE-2020-25483

CRITICAL

UCMS v1.4.8 - Remote Code Execution via Unrestricted File Upload

Title source: llm
STIX 2.1

Description

An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0865
EPSS Percentile 94.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
ucms_project/ucms 1.4.8
Published Oct 23, 2020
Tracked Since Feb 18, 2026