← back
CVE-2020-25042

CVE-2020-25042

23Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 18%
from disclosure to weapon0 days
Published on NVDSep 3
metasploitAug 31
exploitation probability
18%top 3% of all CVEs
observed exploitation
nono source reports it
An arbitrary file upload issue exists in Mara CMS 7.5. In order to exploit this, an attacker must have a valid authenticated (admin/manager) session and make a codebase/dir.php?type=filenew request to upload PHP code to codebase/handler.php.
Affected products
n/a · n/a