This advisory describes an arbitrary file upload vulnerability in AtomatiCMS 10_all via FCKeditor. The vulnerability allows attackers to upload malicious files through specific paths, potentially leading to remote code execution (RCE).
Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:AtomatiCMS 10_all
No auth needed
Prerequisites:Access to the FCKeditor upload endpoints