S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2020-29597 Scanner

CVE-2020-29597 scanner - Unrestricted File Upload vulnerability in IncomCMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
4.6k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-29597
9.8
CVSS

IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows unauthenticated attackers to upload files into the server.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

IncomCMS 2.0 is a comprehensive content management system that is widely used across the world for website and web-based application development. This product provides numerous features and flexibility for digital asset management. With IncomCMS 2.0, website administrators can create, edit and manage content for their websites with ease and speed while seamlessly integrating multimedia content such as images, videos and audio files. 

Among the security risks that threaten digital assets, vulnerabilities in web application software are some of the most notorious. In recent times, one such vulnerability has been discovered in the IncomCMS 2.0 system - CVE-2020-29597. This flaw presents a significant risk to website owners, admins and other stakeholders who take cybersecurity seriously. This particular vulnerability allows unauthenticated attackers to upload rogue files into the server, compromising the security of the system wholly. 

Upon exploitation, this vulnerability can lead to several severe consequences. Attackers may upload malicious and backdoor files, allowing them to access the system's code and data without permission. These backdoors may lead to theft of sensitive data or even complete takeover of the system by attackers. This puts at risk user data, restricted access information, and financial transactions, leading to significant data breaches and unauthorized access. 

In conclusion, the exploitation of the CVE-2020-29597 vulnerability within the IncomCMS 2.0 system is a considerable threat to digital assets, and website administrators need to be vigilant to ensure security measures are in place. By updating their systems, restricting file upload permissions, investing in security services, supervising any uploads and applying strict access controls on sensitive data, website administrators can take effective steps to mitigate risks and prevent attacks. At s4e.io, we offer advanced services that help businesses secure their digital assets, reducing vulnerability risk and mitigating severe data breaches.

 

REFERENCES

Solution Advice

As with any cybersecurity vulnerability, there are precautions that website administrators can take to prevent this vulnerability and protect against potential attacks. Here are some of the best preventative measures they can implement:

  • Update the IncomCMS to the latest version to ensure that the software is up-to-date and that all patches have been applied.
  • Restrict file upload permissions, reducing opportunities for attackers to upload malicious files.
  • Use web application firewalls and network security services to detect and prevent unauthorized attempts to gain access to the server.
  • Supervise any file upload action by authenticated users.
  • Apply strict access control mechanisms to sensitive data.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.