CVE-2020-25537

CRITICAL

UCMS 1.5.0 - Unrestricted Upload of File with Dangerous Type

Title source: llm
STIX 2.1

Description

File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission.

Scores

CVSS v3 9.8
EPSS 0.0183
EPSS Percentile 76.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
ucms_project/ucms 1.5.0
Published Nov 30, 2020
Tracked Since Feb 18, 2026