concrete5 Unrestricted Upload of File with Dangerous Type Vulnerability - CVE-2020-24986 - Vulnerability Database

concrete5 Unrestricted Upload of File with Dangerous Type Vulnerability - CVE-2020-24986

High
Reference: CVE-2020-24986
Title: concrete5 Unrestricted Upload of File with Dangerous Type Vulnerability
Overview:

Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File Manager. It is possible to modify site configuration to upload the PHP file and execute arbitrary commands.