CVE-2020-26678
vfairs
vFairs 3.3 is affected by Remote Code Execution. Any user logged in to a vFairs virtual conference or event can abuse the functionality to upload a profile picture in order to place a malicious PHP file on the server and gain code execution.
- CVSS
- 8.8
- EPSS
- 1.77% 76.0% percentile
- CISA KEV
- Not listed
- Published
- 2021.05.26