Description
Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File Manager. It is possible to modify site configuration to upload the PHP file and execute arbitrary commands.
Remediation
References
Related Vulnerabilities
WordPress Plugin Timeline Event History PHP Object Injection (3.1)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-3541)
WordPress Plugin WooCommerce Blocks SQL Injection (5.5.0)
WordPress Plugin Smart Forms-when you need more than just a contact form Security Bypass (2.6.70)
WordPress Plugin Ninja Forms with File Uploads Extension Cross-Site Scripting (3.3.12)