Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can upload malicious PHP files through the multipart form-data upload endpoint and execute them by accessing the uploaded file path to achieve remote code execution.
Metrics
Affected Vendors & Products
References
History
Sat, 04 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can upload malicious PHP files through the multipart form-data upload endpoint and execute them by accessing the uploaded file path to achieve remote code execution. | |
| Title | Snews CMS 1.7 Unrestricted File Upload via snews_files | |
| First Time appeared |
Snewscms
Snewscms snews |
|
| Weaknesses | CWE-434 | |
| CPEs | cpe:2.3:a:snewscms:snews:1.7:*:*:*:*:*:*:* | |
| Vendors & Products |
Snewscms
Snewscms snews |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-04T16:13:43.576Z
Reserved: 2026-04-04T13:33:00.414Z
Link: CVE-2016-20052
No data.
Status : Received
Published: 2026-04-04T14:16:17.520
Modified: 2026-04-04T14:16:17.520
Link: CVE-2016-20052
No data.
OpenCVE Enrichment
No data.