Files
CVEs-PoC/2020/CVE-2020-5505.md
T
2024-06-18 02:51:15 +02:00

690 B

CVE-2020-5505

Description

Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction with "type":"application/x-php"} to the /api/files/ URI.

POC

Reference

Github