CVE-2020-24036

PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code.
Configurations

Configuration 1

cpe:2.3:a:fork-cms:fork_cms:*:*:*:*:*:*:*:*

Information

Published : 2021-03-04 01:15

Updated : 2021-07-21 11:39


NVD link : CVE-2020-24036

Mitre link : CVE-2020-24036

Products Affected
No products.
CWE
CWE-502

Deserialization of Untrusted Data