Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /themes directory via a crafted zip file uploaded to the Themes panel.
{ "cwe_ids": [ "CWE-434" ], "severity": "HIGH", "github_reviewed_at": "2021-07-08T13:59:31Z", "github_reviewed": true, "nvd_published_at": "2021-07-07T15:15:00Z" }