High severity8.8NVD Advisory· Published Jan 17, 2017· Updated May 13, 2026
CVE-2017-5520
CVE-2017-5520
Description
The media rename feature in GeniXCMS through 0.0.8 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to rename and execute files with the .php6, .php7 and .phtml extensions.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/semplon/GeniXCMS/issues/62nvdExploitIssue TrackingPatchThird Party Advisory
- www.securityfocus.com/bid/95460nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.