YZNCMS
cpe:2.3:a:yzncms:yzncms:*:*:*:*:*:*:*
- 2.0.1
A vulnerability allowing arbitrary file upload has been identified in the plugin installation feature of YZNCMS version 2.0.1. This vulnerability allows attackers to execute arbitrary code by uploading a specially crafted Zip file.
Exploitation of this vulnerability could lead to unauthorized code execution on the server where YZNCMS is installed.
To reproduce this vulnerability, upload a crafted Zip file through the plugin installation feature in YZNCMS version 2.0.1. The uploaded Zip file can be designed to include malicious code that will be executed on the server.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.