Description
lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via an upload of a .php file.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-6434 | lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via an upload of a .php file. |
References
| Link | Providers |
|---|---|
| https://sourceforge.net/p/pivot-weblog/code/4490/ |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T19:42:22.500Z
Reserved: 2017-10-01T00:00:00.000Z
Link: CVE-2017-14958
No data.
Status : Modified
Published: 2017-10-02T01:29:00.470
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-14958
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD