Vulnerability: Remote Code Execution via File Upload in vtecrm vtenext 19 CE

Vulnerability: Remote Code Execution via File Upload in vtecrm vtenext 19 CE

CVE-2020-10228 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A file upload vulnerability in vtecrm vtenext 19 CE allows authenticated users to upload files with a .pht extension, resulting in remote code execution.

Learn more about our Crm Penetration Testing.