Authenticated Unrestricted File Upload Vulnerability in Schlix CMS by Schlix
CVE-2019-11021
7.2HIGH
What is CVE-2019-11021?
The Schlix CMS version 2.1.8-7 contains a vulnerability in the Media Manager that allows authenticated users to upload files without proper restrictions. This oversight potentially enables the upload of malicious PHP files, which can lead to remote code execution on the server. Although this requires administrator permissions, the risk of exploitation exists, posing significant security concerns for sites utilizing outdated versions of Schlix CMS.
