PT-2026-6595 · Unknown+1 · Monstra Cms+1

Publicado

2026-02-05

·

Atualizado

2026-02-06

·

CVE-2025-69906

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Monstra CMS version 3.0.4
Description Monstra CMS version 3.0.4’s Files Manager plugin has an issue where arbitrary files can be uploaded. The application uses a blacklist to validate file extensions and stores uploaded files in a directory accessible via the web. This could allow an attacker to upload files that are executed as code, leading to remote code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-69906

Produtos afetados

File Manager
Monstra Cms