Monstra · Monstra · CVE-2021-40940
**Name of the Vulnerable Software and Affected Versions**
Monstra version 3.0.4
**Description**
The issue is related to an unrestricted file upload vulnerability. This occurs because Monstra does not filter the case of `php`, allowing for potential malicious file uploads.
**Recommendations**
For Monstra version 3.0.4, consider restricting or disabling file upload functionality until a proper fix is implemented to filter and validate uploaded files, especially those with `php` extensions.