Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and previous versions allows a remote unauthenticated malicious user to upload an arbitrary file. As a result, an arbitrary script may be executed and/or a file may be altered.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
shift-tech bingo\\!cms |