← back
CVE-2017-18048

CVE-2017-18048

30Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 63%
from disclosure to weapon0 days
Published on NVDJan 23
metasploitDec 18
exploitation probability
63%top 1% of all CVEs
observed exploitation
nono source reports it
Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lowercase) is blocked but .PHP (uppercase) is not.
Affected products
n/a · n/a