CVE-2020-25537

CRITICAL

Ucms - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission.

Scores

CVSS v3 9.8
EPSS 0.0040
EPSS Percentile 60.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
ucms_project/ucms 1.5.0
Published Nov 30, 2020
Tracked Since Feb 18, 2026