CVE-2015-6568

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
14/04/2017
Last modified:
20/04/2025

Description

Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent a change of a file extension to ".php" after originally using the parameter "filename" for uploading a JPEG image. Exploitation requires a registered user who has access to upload functionality.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wolfcms:wolf_cms:*:*:*:*:*:*:*:* 0.8.3 (including)