Record summary

CVE-2021-39608 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit.

Description

Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a remote malicious user exeuct arbitrary php code.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBFlatCore CMS 2.0.7 - Remote Code Execution (RCE) (Authenticated)ExploitDB exploitby Mason Soroka-GillNot analyzed1 file
ExploitDB

PoC details

References

3