CVE-2018-12914: Malicious File Upload
Published Jun 27, 2018
·Updated
A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a directory traversal pathname. After an unzip operation, the attacker can execute arbitrary code by visiting a .jsp URI.
Affected Software
1 affected component
PublicCMS publiccms=4.0.20180210
Event History
Jun 27, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-12914.
2
What is the severity level of CVE-2018-12914?
CVE-2018-12914 has a severity level of critical.
3
How does CVE-2018-12914 affect PublicCMS?
CVE-2018-12914 affects PublicCMS version 4.0.20180210.
4
What can an attacker do with CVE-2018-12914?
An attacker can upload a ZIP archive containing a .jsp file with a directory traversal pathname and execute arbitrary code by visiting a .jsp URI.
5
Is there a fix available for CVE-2018-12914?
Yes, a fix has been provided by the PublicCMS team. It is recommended to update to a version that includes the fix.