ZeroHour

CVE-2018-6383

PoC ×3
CVSS 3.1
8.8 high
EPSS
13%p96
Published
()
Modified
Description

Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extension, which allows remote authenticated Admins or Editors to execute arbitrary PHP code by uploading a file, a different vulnerability than CVE-2017-18048.

Vendors
monstra
Products
monstra
Weakness
CWE-184
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.