CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2016-20052 — Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows una...

Saturday, April 4, 2026 at 02:16 PM UTC·Source: NIST NVD

Updated: Monday, April 6, 2026 at 12:17 AM UTC

Executive Summary

Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can upload malicious PHP files through the multipart form-data upload endpoint and execute them by accessing the uploaded file path to achieve remote code execution.

Analysis

Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can upload malicious PHP files through the multipart form-data upload endpoint and execute them by accessing the uploaded file path to achieve remote code execution. CVSS Score: 9.8. Published: 2026-04-04T14:16:17.520.

Indicators of Compromise (1)

CVE (1)
CVE-2016-20052
Source Attribution

Originally published by NIST NVD on Apr 4, 2026. Verified by: NIST.

Related Threats