Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Wuhuaviator

#26257of 53,633
9.8Total CVSS
Vulnerabilities · 1
PT-2022-11339
9.8
2022-06-15
Monstra · Monstra · CVE-2021-40940
**Name of the Vulnerable Software and Affected Versions** Monstra version 3.0.4 **Description** The issue is related to an unrestricted file upload vulnerability. This occurs because Monstra does not filter the case of `php`, allowing for potential malicious file uploads. **Recommendations** For Monstra version 3.0.4, consider restricting or disabling file upload functionality until a proper fix is implemented to filter and validate uploaded files, especially those with `php` extensions.