PT-2017-13779 · Pivotx · Pivotx

Hansfn

·

Published

2017-10-01

·

Updated

2017-10-06

·

CVE-2017-14958

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PivotX version 2.3.11
Description The issue concerns the improper blocking of uploads of dangerous file types by admin users in lib.php, allowing remote PHP code execution via an upload of a .php file.
Recommendations For PivotX version 2.3.11, update to a version that properly blocks uploads of dangerous file types to prevent remote PHP code execution.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-14958

Affected Products

Pivotx