High severity8.8NVD Advisory· Published Mar 4, 2021· Updated Jul 9, 2026
CVE-2020-24036
CVE-2020-24036
Description
PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- ForkCMS/ForkCMSdescription
Patches
Vulnerability mechanics
References
4- seclists.org/fulldisclosure/2021/Mar/31nvdExploitMailing ListThird Party Advisory
- tech.feedyourhead.at/content/ForkCMS-PHP-Object-Injection-CVE-2020-24036nvdExploitPatchThird Party Advisory
- www.ait.ac.at/themen/cyber-security/pentesting/security-advisories/ait-sa-20210215-04nvdExploitPatchThird Party Advisory
- packetstormsecurity.com/files/161764/ForkCMS-PHP-Object-Injection.htmlnvd
News mentions
0No linked articles in our index yet.