PT-2018-12490 · Phpcms · Phpcms

Published

2018-07-19

·

Updated

2024-02-14

·

CVE-2018-14399

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPCMS version 9.6.0
Description The issue allows remote attackers to upload and execute arbitrary PHP code. This can be achieved by sending a .txt?.php#.jpg URI in the SRC attribute of an IMG element within info[content] JSON data to the "index.php?m=member&c=index&a=register" API endpoint.
Recommendations For PHPCMS version 9.6.0, consider restricting access to the index.php?m=member&c=index&a=register API endpoint to minimize the risk of exploitation. Avoid using the info[content] JSON data in this endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2018-14399

Affected Products

Phpcms