CVE-2020-18912
Published Aug 29, 2023An issue found in Earcms Ear App v.20181124 allows a remote attacker to execute arbitrary code via the uload/index-uplog.php.
Vendor archive
2 CVEs tagged to vendor earcms — 1 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.
An issue found in Earcms Ear App v.20181124 allows a remote attacker to execute arbitrary code via the uload/index-uplog.php.
In Earcms Ear Music through 4.1 build 20170710, remote authenticated users can execute arbitrary PHP code by changing the allowable music-upload extensions to include .php in addi…