Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extension, which allows remote authenticated Admins or Editors to execute arbitrary PHP code by uploading a file, a different vulnerability than CVE-2017-18048.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-01-29T18:00:00

Updated: 2022-01-28T12:29:29

Reserved: 2018-01-29T00:00:00


Link: CVE-2018-6383

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-01-29T18:29:00.220

Modified: 2022-02-10T07:23:42.530


Link: CVE-2018-6383

JSON object: View

cve-icon Redhat Information

No data.

CWE