Arbitrary File Upload Vulnerability in PHPFusion by PHPFusion
CVE-2021-40188

7.2HIGH

Key Information:

Vendor

PHP-fusion

Status
Vendor
CVE Published:
11 October 2021

What is CVE-2021-40188?

PHPFusion version 9.03.110 contains an arbitrary file upload vulnerability in its File Manager functionality within the admin panel. The application does not properly filter certain PHP file extensions, allowing attackers to upload malicious files. This could lead to remote code execution on the server, posing significant security risks to web applications using this version.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.