Description
PHPFusion 9.03.110 is affected by an arbitrary file upload vulnerability. The File Manager function in admin panel does not filter all PHP extensions such as ".php, .php7, .phtml, .php5, ...". An attacker can upload a malicious file and execute code on the server.
References
https://github.com/PHPFusion/PHPFusion/issues/2372
ExploitIssue TrackingThird Party Advisory
https://github.com/PHPFusion/PHPFusion/issues/2372
ExploitIssue TrackingThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
7.2 · High
Information
Source identifier
Vulnerability status
Modified
Published
2021-10-11T17:15:07.547Z
4 years agoLast modified
2024-11-21T05:23:44.850Z
1 year ago