PoC Index

CVE-2018-20166

HIGH 8.8EPSS 7.1%

A file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a background image, and mishandles extension checking. It accepts uploads of PHP content if the first few characters match GIF data, and the filename ends in ".php" with mixed case, such as the .pHp extension.

CVSS v3.0
8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
7.12% chance of exploitation in the next 30 days, 94th percentile
Published
2019-01-02
Updated
2024-08-05

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related