Arbitrary Code Execution Vulnerability in Monstra CMS 3.0.4 via Crafted Payload in Snippet Content Field

Arbitrary Code Execution Vulnerability in Monstra CMS 3.0.4 via Crafted Payload in Snippet Content Field

CVE-2020-23219 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit Snippet" module.

Learn more about our Cms Pen Testing.