Zenar CMS 9.3 suffers from an unrestricted file upload vulnerability in its file management module, allowing authenticated attackers (with minimal privileges) to upload arbitrary files, including malicious PHP scripts, to the web server. # CVE-2022-44136-poc
Zenar CMS 9.3 suffers from an unrestricted file upload vulnerability in its file management module, allowing authenticated attackers (with minimal privileges) to upload arbitrary files, including malicious PHP scripts, to the web server. Due to insufficient file extension validation and improper sanitization, an attacker can execute arbitrary code on the target system by uploading a crafted payload (e.g., a web shell) and accessing it via the web root.
[4.0K] /data/pocs/b412c732201468e134a18e505294959767a4663e
├── [5.0K] CVE-2022-44136-EXP.py
└── [ 490] README.md
0 directories, 2 files