CVE-2018-18086: Malicious File Upload
Published Oct 9, 2018
·Updated
EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users.
Affected Software
1 affected component
Phome Empirecms=7.5
Event History
Oct 9, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18086?
CVE-2018-18086 is classified as a high severity vulnerability due to its arbitrary file upload capability.
2
How do I fix CVE-2018-18086?
To mitigate CVE-2018-18086, update EmpireCMS to the latest version or implement access controls to restrict file upload functionalities.
3
Who is affected by CVE-2018-18086?
CVE-2018-18086 affects users of EmpireCMS version 7.5, particularly those with login permissions.
4
What type of attack can exploit CVE-2018-18086?
CVE-2018-18086 can be exploited by authenticated users to upload malicious files to the server.
5
Is CVE-2018-18086 easy to exploit?
Yes, CVE-2018-18086 is relatively easy to exploit for those with access to the affected system.