CVE-2017-18048
HIGH 8.8EPSS 63.4%
Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lowercase) is blocked but .PHP (uppercase) is not.
- CVSS v3.0
- 8.8 HIGH
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P - EPSS
- 63.35% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2018-01-23
- Updated
- 2024-08-05
Proof-of-concept exploits (2)
- https://securityprince.blogspot.in/2017/12/monstra-cms-304-arbitrary-file-upload.html
- https://www.exploit-db.com/exploits/43348/