
CVE-2020-37071 CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a crafted payload. … https://www.cve.org/CVERecord?id=CVE-2020-37071
Post summary
CVE-2020-37071 is a deserialization flaw in CraftCMS 3 vCard Plugin 1.0.0 that permits unauthenticated attackers to run arbitrary PHP code via a crafted payload, yet no PoC, exploit code, or patch information is provided.


