ZeroHour

CVE-2017-14958

CVSS 3.0
7.2 high
EPSS
1%p69
Published
()
Modified
Description

lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via an upload of a .php file.

Vendors
pivotx
Products
pivotx
Weakness
CWE-434
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.