Vulnerability Details CVE-2020-25483
An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.491
EPSS Ranking 97.6%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2020-25483
-
cpe:2.3:a:ucms_project:ucms:1.4.8