Medium severity4.3NVD Advisory· Published Jan 30, 2026· Updated Jun 17, 2026
CVE-2020-37054
CVE-2020-37054
Description
Navigate CMS 2.8.7 contains a cross-site request forgery vulnerability that allows attackers to upload malicious extensions through a crafted HTML page. Attackers can trick authenticated administrators into executing arbitrary file uploads by leveraging the extension upload functionality without additional validation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <2.8.7
- Naviwebs S.C./Navigate CMSv5Range: 2.8.7
- cpe:2.3:a:naviwebs:navigate_cms:2.8.7:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- www.exploit-db.com/exploits/48548nvdExploitThird Party AdvisoryVDB Entry
- sourceforge.net/projects/navigatecmsnvdProduct
- www.navigatecms.com/en/homenvdProduct
- www.vulncheck.com/advisories/navigate-cms-cross-site-request-forgerynvdBroken Link
News mentions
0No linked articles in our index yet.