mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-13 18:22:07 +02:00
836 B
836 B
CVE-2020-35657
Description
Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of UploadTheme to upload a theme ZIP archive containing a .php file that is able to execute OS commands. NOTE: this is unrelated to the JAWS (aka Job Access With Speech) product.
POC
Reference
No PoCs from references.