← Back to CVE List

CVE-2020-28173

Published: 2021-03-31T13:15Z
Last Modified: 2024-11-21T05:22Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Simple College Website 1.0 allows a user to conduct remote code execution via /alumni/admin/ajax.php?action=save_settings when uploading a malicious file using the image upload functionality, which is stored in /alumni/admin/assets/uploads/. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt