ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-37023”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-37023
Published
2026-01-30
CVSS:
8.7
ShadowTrackr CVSS:
6.3
Summary:
Koken CMS 0.22.24 contains a file upload vulnerability that allows authenticated attackers to bypass file extension restrictions by renaming malicious PHP files. Attackers can upload PHP files with system command execution capabilities by manipulating the file upload request through a web proxy and changing the file extension.