← Back to CVE List
CVE-2020-20588
File upload vulnerability in function upload in action/Core.class.php in zhimengzhe iBarn 1.5 allows remote attackers to run arbitrary code via avatar upload to index.php.
> MITRE Terms of Use apply – see LICENSE‑MITRE.txt