CRITICAL
job/uploadfile_save.php in MetInfo through 5.3.17 blocks the .php extension but not related extensions, which might allow remote authenticated admins to execute arbitrary PHP code by uploading a .phtml file after certain actions involving admin/system/safe.php and job/cv.php
Published Jul 28, 2017
9.8
CRITICALCVSS 3.0
EPSS 1.49%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.