PT-2025-31690 · Unknown · Lavalite Cms

Published

2025-08-01

·

Updated

2025-08-01

·

CVE-2013-10055

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Havalite CMS versions 1.1.7 and earlier
Description An unauthenticated arbitrary file upload issue exists in the upload.php script. The application does not properly validate file extensions or enforce authentication checks, allowing remote attackers to upload malicious PHP files using a crafted multipart/form-data POST request. Uploaded files can be accessed directly under havalite/tmp/files/, potentially leading to remote code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2013-10055

Affected Products

Lavalite Cms