CVE-2018-6383

8.8HIGH

Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extension, which allows remote authenticated Admins or Edi

发布于: 1/29/2018更新于: 11/21/2024

描述

Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extension, which allows remote authenticated Admins or Editors to execute arbitrary PHP code by uploading a file, a different vulnerability than CVE-2017-18048.

AI分析AI驱动

受影响产品

monstramonstra

可用漏洞利用 (1)

参考资料