CVE detail
CVE-2020-15189 — CVE-2020-15189
Published 2020-09-18 · Modified 2026-06-17 · Vendor brassica · Product soy_cms · Source nvd
MEDIUM
severity
CVSS-derived band
0.0281
EPSS probability
exploitation probability, 30d
85.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
SOY CMS 3.0.2 and earlier is affected by Remote Code Execution (RCE) using Unrestricted File Upload. Cross-Site Scripting(XSS) vulnerability that was used in CVE-2020-15183 can be used to increase impact by redirecting the administrator to access a specially crafted page. This vulnerability is caused by insecure configuration in elFinder. This is fixed in version 3.0.2.328.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References