Home
MEDIUM: 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:LMEDIUM: 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L 6.7 and earlier (PowerCMS 6.x series)
affected
5.3 and earlier (PowerCMS 5.x series)
affected
4.6 and earlier (PowerCMS 4.x series)
affected
Description
Multiple versions of PowerCMS allow unrestricted upload of dangerous files. If a product administrator accesses a malicious file uploaded by a product user, an arbitrary script may be executed on the browser.
Problem types
Unrestricted upload of file with dangerous type
Product status
References
www.powercms.jp/news/release-powercms-671-531-461.html