PT-2018-12449 · Joyplus · Joyplus-Cms

Published

2018-07-17

·

Updated

2018-09-17

·

CVE-2018-14334

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions joyplus-cms version 1.6.0
Description The issue allows for arbitrary file upload due to insufficient detection of prohibited file extensions in the manager/editor/upload.php file. This can lead to the upload and execution of a .php file.
Recommendations For joyplus-cms version 1.6.0, consider restricting access to the upload functionality in manager/editor/upload.php until a proper fix is implemented to prevent the upload of malicious files, such as .php files. As a temporary workaround, consider adding additional validation to ensure that only allowed file types can be uploaded.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-14334

Affected Products

Joyplus-Cms