CVE advisoryCRITICAL
CVE-2016-20052
Snews CMS 1.7 Unrestricted File Upload Leads to Remote Code Execution.
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A critical vulnerability in Snews CMS allows unauthenticated attackers to upload and execute arbitrary files, including PHP executables, potentially leading to remote code execution. This issue impacts the content management system, and its relevance and exposure need to be assessed.