Koken CMS 0.22.24 contains a file upload vulnerability that allows authenticated attackers to bypass file extension restrictions by renaming malicious PHP files. Attackers can upload PHP files with system command execution capabilities by manipulating the file upload request through a web proxy and changing the file extension.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-30 23:16
Updated : 2026-01-30 23:16
NVD link : CVE-2020-37023
Mitre link : CVE-2020-37023
CVE.ORG link : CVE-2020-37023
JSON object : View
Products Affected
No product.
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
