Description
An arbitrary file upload vulnerability in the component /workplace#!explorer of Alkacon OpenCMS v15.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.
Remediation
References
https://www.exploit-db.com/exploits/51564
Related Vulnerabilities
CVE-2019-10799 Vulnerability in npm package compile-sass
CVE-2021-32859 Vulnerability in npm package baremetrics-calendar
CVE-2022-25931 Vulnerability in npm package easy-static-server
CVE-2020-8908 Vulnerability in maven package com.google.guava:guava
CVE-2020-5245 Vulnerability in maven package io.dropwizard:dropwizard-validation