CVE-2020-20691

An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploading crafted HTML files.
References
Link Resource
https://github.com/monstra-cms/monstra/issues/461 Exploit Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:monstra:monstra_cms:3.0.4:*:*:*:*:*:*:*

History

08 Oct 2021, 14:58

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 5.8
v3 : 6.5
References (MISC) https://github.com/monstra-cms/monstra/issues/461 - (MISC) https://github.com/monstra-cms/monstra/issues/461 - Exploit, Issue Tracking, Third Party Advisory
CPE cpe:2.3:a:monstra:monstra_cms:3.0.4:*:*:*:*:*:*:*
CWE CWE-434

27 Sep 2021, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-09-27 22:15

Updated : 2024-02-04 22:08


NVD link : CVE-2020-20691

Mitre link : CVE-2020-20691

CVE.ORG link : CVE-2020-20691


JSON object : View

Products Affected

monstra

  • monstra_cms
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type