Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests parameter of the upload function.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Fuel_cms | Thedaylightstudio | 1.4.6 (including) | 1.4.6 (including) |
References