CVE-2021-39608
HIGHFlatCore-CMS 2.0.7 - Remote Code Execution via Upload Addon Plugin
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-39608. PoCs published by Mason Soroka-Gill.
AI-analyzed exploit summary This exploit demonstrates an authenticated RCE vulnerability in FlatCore CMS 2.0.7 by uploading a malicious PHP plugin via the admin panel. It leverages a CSRF token bypass and file upload functionality to execute arbitrary commands.
Description
Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a remote malicious user exeuct arbitrary php code.
Exploits (1)
This exploit demonstrates an authenticated RCE vulnerability in FlatCore CMS 2.0.7 by uploading a malicious PHP plugin via the admin panel. It leverages a CSRF token bypass and file upload functionality to execute arbitrary commands.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H