VYPR
Medium severity6.5NVD Advisory· Published Jun 3, 2021· Updated Jun 17, 2026

CVE-2020-21005

CVE-2020-21005

Description

WellCMS 2.0 beta3 is vulnerable to File Upload. A user can log in to the CMS background and upload a picture. Because the upload file type is controllable, the user can modify the upload file type to get webshell.

Affected products

3
  • WellCMS/WellCMSdescription
  • WellCMS/WellCMSllm-fuzzy2 versions
    2.0 beta3+ 1 more
    • (no CPE)range: 2.0 beta3
    • cpe:2.3:a:wellcms:wellcms:2.0:beta3:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.