Vulnerabilities > Bookstackapp > Bookstack > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-03-09 CVE-2020-5256 Unrestricted Upload of File with Dangerous Type vulnerability in Bookstackapp Bookstack
BookStack before version 0.25.5 has a vulnerability where a user could upload PHP files through image upload functions, which would allow them to execute code on the host system remotely.
network
low complexity
bookstackapp CWE-434
critical
9.0