CVE-2016-20052 is a critical vulnerability in Snews CMS 1.7 that allows unauthenticated attackers to upload arbitrary files, including PHP executables, to the snews_files directory. This can be achieved through the multipart form-data upload endpoint, enabling remote code execution by accessing the uploaded file path. The vulnerability has a CVSS score of 9.3, indicating a critical severity level. Adminis [truncated]
CVE-2016-20051 is a cross-site request forgery vulnerability in Snews CMS 1.7. Attackers can craft malicious HTML forms to trick authenticated administrators into changing their credentials. This vulnerability has a medium severity due to its CVSS score of 6.9. The vulnerability allows attackers to modify admin username and password parameters without authentication.