HIGH
An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs Navigate CMS 2.8 allows authenticated attackers to achieve remote code execution via a POST request with engine=picnik and id=../../../navigate_info.php
Published Oct 3, 2018
8.8
HIGHCVSS 3.0
EPSS 78.99%
Description
Affected products
Remediation
References (4)
Change history (0)
No recorded changes yet.