CVE-2017-14958
—CVSS 3.0
7.2 high
EPSS
1%p69
Published
()
Modified
Description
lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via an upload of a .php file.
- Vendors
- pivotx
- Products
- pivotx
- Weakness
- CWE-434
- Vector
- CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.