Review reviewHigh
CVE-2020-24036
fork cms
PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code.
- CVSS
- 8.8
- EPSS
- 2.94% 85.8% percentile
- CISA KEV
- Not listed
- Published
- 2021.03.04