Arbitrary File Upload Vulnerability in BigTree CMS 4.4.16 Allows Remote Code Execution via Crafted PDF File

Arbitrary File Upload Vulnerability in BigTree CMS 4.4.16 Allows Remote Code Execution via Crafted PDF File

CVE-2022-36197 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

BigTree CMS 4.4.16 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PDF file.

Learn more about our Cms Pen Testing.