CVE-2018-10469: Malicious File Upload
Published Apr 27, 2018
·Updated
b3log Symphony (aka Sym) 2.6.0 allows remote attackers to upload and execute arbitrary JSP files via the name[] parameter to the /upload URI.
Affected Software
1 affected component
b3log Symphony=2.6.0
Event History
Apr 27, 2018
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-10469?
CVE-2018-10469 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2018-10469?
To fix CVE-2018-10469, update b3log Symphony to version 2.6.1 or later.
3
What type of attack is possible with CVE-2018-10469?
CVE-2018-10469 allows remote attackers to upload and execute arbitrary JSP files.
4
Which version of b3log Symphony is affected by CVE-2018-10469?
CVE-2018-10469 affects b3log Symphony version 2.6.0.
5
What is the primary vulnerability mechanism of CVE-2018-10469?
The vulnerability is caused by improper validation of the name[] parameter in the /upload URI.