Beware: flatCore CMS Vulnerability Allows Sneaky PHP File Uploads!
FlatCore CMS is having a wardrobe malfunction with its file upload security, allowing arbitrary .php file uploads. Just sneak past the admin login, throw on a malicious PHP ensemble, and strut down the server runway. But remember, only do this in the name of ethical hacking and responsible disclosure!

Hot Take:
Who knew flatCore CMS was so hospitable to unwanted guests? This exploit turns their ‘welcome mat’ into a red carpet for PHP backdoors, making your server the hottest destination for nefarious code!
Key Points:
- flatCore CMS versions 1.5.5 and 1.4.7 are vulnerable to arbitrary PHP file uploads.
- Exploits require administrative access to the flatCore Admin Panel.
- Malicious files can be uploaded through the “Media” or “Addons” sections.
- Post-upload, files are accessible and executable, leading to potential server compromise.
- CVE-2019-10652 has been assigned to this vulnerability.
Already a member? Log in here