Back to CVE List

CVE-2018-25409

HIGH SEVERITY

CVSS Score & Metrics

Base Score
8.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

SIM-PKH 2.4.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by submitting PHP code through the fupload parameter. Attackers can upload PHP files via the aksi_pengurus.php endpoint with module=pengurus and act=update parameters, which are stored in the foto directory and executed as web scripts.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-434
Source
NVD
Vendor
Simpkh
Product
SIM-PKH

External References

Discussion (0)

Add Comment

No comments yet. Be the first!