Record summary

CVE-2020-37227 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.

Description

HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerability that allows authenticated users to bypass client-side file extension validation by uploading arbitrary files. Attackers can intercept upload requests to the logoupload parameter in the admin interface and rename files to executable extensions .php to achieve remote code execution.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 18, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List2.1affected

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin HS Brand Logo Slider 2.1 - 'logoupload' File UploadExploitDB exploitby Net-HunterNot analyzed1 file
ExploitDB

PoC details

References

5