CVE-2020-14067 describes a critical arbitrary file upload vulnerability in Navigate CMS versions 2.9 and earlier. The flaw allows attackers to bypass file extension checks by using the .phtml extension within ZIP archives during theme or extension installation, enabling the upload and execution of malicious PHP code. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network with no authentication or user interaction required, potentially leading to complete system compromise (confidentiality, integrity, and availability). While no public exploits or active exploitation have been observed, and community discussion is minimal, the high severity warrants immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.9CPE matchmatch criteria | cpe:2.3:a:naviwebs:navigatecms:2.9:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.