Arbitrary File Upload Vulnerability in Artworks Gallery by Code Projects
CVE-2020-28687

8.8HIGH

What is CVE-2020-28687?

The edit profile functionality in Artworks Gallery version 1.0 allows remote attackers to exploit an arbitrary file upload vulnerability. This issue can lead to serious security risks as attackers can upload malicious files that may be executed on the server, compromising the integrity of the web application. Proper validation and sanitization of file uploads are essential to mitigate this threat.

References

EPSS Score

11% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.