Unrestricted File Upload Vulnerability in BlackCat CMS by BlackCat
CVE-2017-14399

8.8HIGH

Key Information:

Vendor
CVE Published:
12 September 2017

What is CVE-2017-14399?

An unrestricted file upload vulnerability exists in BlackCat CMS version 1.2.2, which allows attackers to upload files with malicious code by changing the file extension from .jpg to .php. This flaw in the backend media handling can lead to severe consequences, including unauthorized file execution and server compromise. It is essential for users to apply security patches and follow best practices in file upload handling to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.
CVE-2017-14399 : Unrestricted File Upload Vulnerability in BlackCat CMS by BlackCat