An issue was discovered in laravelCMS through 2018-04-02. \app\Http\Controllers\Backend\ProfileController.php allows upload of arbitrary PHP files because the file extension is not properly checked and uploaded files are not properly renamed.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-16T16:58:59.268Z

Reserved: 2018-10-31T00:00:00Z

Link: CVE-2018-18888

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-11-01T01:29:00.330

Modified: 2024-11-21T03:56:49.670

Link: CVE-2018-18888

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.