HIGH

CVE-2020-10963

CVSS v3

7.2

HIGH

EPSS Score

24.0%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/file_upload image upload with PHP content within a GIF image that has the .php extension. NOTE: this product is discontinued.

Technical details

Published
3/25/2020

Frequently asked questions

What is CVE-2020-10963?

FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/file_upload image upload with PHP content within a GIF image that has the .php extension. NOTE: this product is discontinued.

Is CVE-2020-10963 actively exploited?

Active exploitation of CVE-2020-10963 has not been confirmed. The EPSS score is 24.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-10963?

CVE-2020-10963 has a CVSS v3 base score of 7.2 (HIGH severity).

Is CVE-2020-10963 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.