Cuyahoga before 1.0.1 installs the FCKEditor component with an incorrect deny statement in a Web.config file, which allows remote attackers to upload files when these privileges were intended only for the Administrator and Editor roles.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 65.4%