Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /themes directory via a crafted zip file uploaded to the Themes panel.
{ "nvd_published_at": "2021-07-07T15:15:00Z", "github_reviewed_at": "2021-07-08T13:59:31Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-434" ] }