CVE-2017-5520: Metalgenix Genixcms
High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.
The media rename feature in GeniXCMS through 0.0.8 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to rename and execute files with the `.php6`, `.php7` and `.phtml` extensions.
Affected products
- Metalgenix Genixcms: up to and including 0.0.8
Published 2017-01-17. Last modified 2026-06-17.