CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. It may be remotely exploitable.
CVE
CVE-2017-16920
Severity
CRITICAL
CVSS
9.8
EPSS
2.14%
Original NVD Description
v5/config/system.php in dayrui FineCms 5.2.0 has a default SYS_KEY value and does not require key regeneration for each installation, which allows remote attackers to upload arbitrary .php files via a member api swfupload action to index.php.
Related CVEs
Other vulnerabilities affecting the same vendor(s)