CVE-2020-15189: Brassica Soy CMS
High severity, CVSS 7.2. EPSS: 2.8% chance of exploitation in the next 30 days.
SOY CMS 3.0.2 and earlier is affected by Remote Code Execution (RCE) using Unrestricted File Upload. Cross-Site Scripting(XSS) vulnerability that was used in CVE-2020-15183 can be used to increase impact by redirecting the administrator to access a specially crafted page. This vulnerability is caused by insecure configuration in elFinder. This is fixed in version 3.0.2.328.
Affected products
- Brassica Soy CMS: before 3.0.2.328 (fixed in 3.0.2.328)
Published 2020-09-18. Last modified 2026-06-17.