Vulnerabilities > Flatcore > Flatcore CMS > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-08-23 CVE-2021-39608 Unrestricted Upload of File with Dangerous Type vulnerability in Flatcore Flatcore-Cms 2.0.7
Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a remote malicious user exeuct arbitrary php code.
network
low complexity
flatcore CWE-434
critical
9.0