CVE-2018-19422: Malicious File Upload
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these.
Other sources
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-19422?
CVE-2018-19422 is a vulnerability in Subrion CMS 4.2.1 that allows remote attackers to execute arbitrary PHP code via a .pht or .phar file.
How does the vulnerability in Subrion CMS 4.2.1 occur?
The vulnerability occurs in the /panel/uploads directory and is caused by the .htaccess file omitting .pht and .phar files.
What is the severity of CVE-2018-19422?
The severity of CVE-2018-19422 is high, with a severity value of 7.2.
What software is affected by CVE-2018-19422?
Subrion CMS 4.2.1 and Intelliants Subrion CMS are affected by CVE-2018-19422.
How can I fix CVE-2018-19422?
To fix CVE-2018-19422, update Subrion CMS to version 4.2.2 or higher.