Описание
Unrestricted Upload of File with Dangerous Type in MODX Revolution
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.
Пакеты
Наименование
modx/revolution
composer
Затронутые версииВерсия исправления
<= 2.8.3-pl
Отсутствует
Связанные уязвимости
CVSS3: 7.2
nvd
почти 4 года назад
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.