Exploitation Summary
CVE-2020-27387 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 1 public exploit from researchers including Erik Wynter, including a Metasploit module exploits/multi/http/horizontcms_upload_exec.
AI-analyzed exploit summary This Metasploit module exploits an arbitrary file upload vulnerability in HorizontCMS 1.0.0-beta to execute arbitrary commands by uploading a malicious PHP file and renaming it to bypass server-side restrictions.
Description
An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the FileManager) to upload and execute arbitrary PHP code by uploading a PHP payload, and then using the FileManager's rename function to provide the payload (which will receive a random name on the server) with the PHP extension, and finally executing the PHP file via an HTTP GET request to /storage/<php_file_name>. NOTE: the vendor has patched this while leaving the version number at 1.0.0-beta.
Exploits (1)
This Metasploit module exploits an arbitrary file upload vulnerability in HorizontCMS 1.0.0-beta to execute arbitrary commands by uploading a malicious PHP file and renaming it to bypass server-side restrictions.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H