Files
CVEs-PoC/2020/CVE-2020-19890.md
T
2024-05-25 21:48:12 +02:00

675 B

CVE-2020-19890

Description

DBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as there is no filter function for security, you can read any file's content.

POC

Reference

Github