Back to Database
Status published
Unknown
CVE-2020-19786
File upload vulnerability in CSKaza CSZ CMS v.1.2.2 fixed in...
Vulnerability Description
File upload vulnerability in CSKaza CSZ CMS v.1.2.2 fixed in v1.2.4 allows attacker to execute aritrary commands and code via crafted PHP file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-19786
Credits & Attribution
No credits recorded in the NVD database.
References
More from cszcms
View All →CVE-2024-58307
CSZCMS 1.3.0 Authenticated SQL Injection via Members View Endpoint
Critical
9.3
CVE-2022-28997
CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery...
High
7.5
CVE-2022-27165
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatus...
Critical
9.8
CVE-2022-27164
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUsers...
Critical
9.8
CVE-2022-27163
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_editUser...
Critical
9.8
Affected Vendor
cszcms
View all reports →Affected Software
csz cms
Vulnerable Versions:
1.2.2
Timeline
Official Publish:
March 23rd, 2023
Last Modified:
February 25th, 2025
Added to House:
July 21st, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.