ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-19302”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-19302
Published
2021-08-03
CVSS:
9.8
ShadowTrackr CVSS:
8.2
Summary:
An arbitrary file upload vulnerability in the avatar upload function of vaeThink v1.0.1 allows attackers to open a webshell via changing uploaded file suffixes to ".php".