VYPR
High severity8.8NVD Advisory· Published Oct 5, 2020· Updated Jun 17, 2026

CVE-2020-26048

CVE-2020-26048

Description

The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within an image extension and through a custom request using the rename function provided by the file manager is able to modify the image extension into PHP resulting in remote arbitrary code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • CuppaCMS/CuppaCMSdescription
  • Cuppacms/Cuppacmsllm-fuzzy2 versions
    <2019-11-12+ 1 more
    • (no CPE)range: <2019-11-12
    • cpe:2.3:a:cuppacms:cuppacms:*:*:*:*:*:*:*:*range: <2019-11-12

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.