PT-2018-12449 · Joyplus · Joyplus-Cms
Published
2018-07-17
·
Updated
2018-09-17
·
CVE-2018-14334
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
joyplus-cms version 1.6.0
Description
The issue allows for arbitrary file upload due to insufficient detection of prohibited file extensions in the manager/editor/upload.php file. This can lead to the upload and execution of a .php file.
Recommendations
For joyplus-cms version 1.6.0, consider restricting access to the upload functionality in manager/editor/upload.php until a proper fix is implemented to prevent the upload of malicious files, such as .php files. As a temporary workaround, consider adding additional validation to ensure that only allowed file types can be uploaded.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Joyplus-Cms