VYPR
Critical severity9.8NVD Advisory· Published Mar 14, 2019· Updated Jun 17, 2026

CVE-2019-9825

CVE-2019-9825

Description

FeiFeiCMS 4.1.190209 allows remote attackers to upload and execute arbitrary PHP code by visiting index.php?s=Admin-Index to modify the set of allowable file extensions, as demonstrated by adding php to the default jpg,gif,png,jpeg setting, and then using the "add article" feature.

Affected products

2
  • cpe:2.3:a:feifeicms:feifeicms:4.1.190209:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:feifeicms:feifeicms:4.1.190209:*:*:*:*:*:*:*
    • (no CPE)range: = 4.1.190209

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.