Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gcf9-q9xj-jjx5

Опубликовано: 05 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extension validation and stores uploaded files directly in a web-accessible directory. Under typical server configurations, this can allow an attacker to upload files that are interpreted as executable code, resulting in remote code execution.

Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extension validation and stores uploaded files directly in a web-accessible directory. Under typical server configurations, this can allow an attacker to upload files that are interpreted as executable code, resulting in remote code execution.

EPSS

Процентиль: 43%
0.00209
Низкий

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
3 дня назад

Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extension validation and stores uploaded files directly in a web-accessible directory. Under typical server configurations, this can allow an attacker to upload files that are interpreted as executable code, resulting in remote code execution.

EPSS

Процентиль: 43%
0.00209
Низкий

8.8 High

CVSS3

Дефекты

CWE-434