First published: Wed Jun 27 2018(Updated: )
A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a directory traversal pathname. After an unzip operation, the attacker can execute arbitrary code by visiting a .jsp URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
sanluan PublicCMS | =4.0.20180210 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-12914.
CVE-2018-12914 has a severity level of critical.
CVE-2018-12914 affects PublicCMS version 4.0.20180210.
An attacker can upload a ZIP archive containing a .jsp file with a directory traversal pathname and execute arbitrary code by visiting a .jsp URI.
Yes, a fix has been provided by the PublicCMS team. It is recommended to update to a version that includes the fix.