First published: Wed Nov 21 2018(Updated: )
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/intelliants/subrion | <=4.2.1 | 4.2.2 |
Intelliants Subrion CMS | =4.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19422 is a vulnerability in Subrion CMS 4.2.1 that allows remote attackers to execute arbitrary PHP code via a .pht or .phar file.
The vulnerability occurs in the /panel/uploads directory and is caused by the .htaccess file omitting .pht and .phar files.
The severity of CVE-2018-19422 is high, with a severity value of 7.2.
Subrion CMS 4.2.1 and Intelliants Subrion CMS are affected by CVE-2018-19422.
To fix CVE-2018-19422, update Subrion CMS to version 4.2.2 or higher.