CVE-2018-14441

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
20/07/2018
Last modified:
14/09/2018

Description

An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. admin/admin/fileUploadAction_fileUpload.action allows arbitrary file upload, as demonstrated by a .jsp file with the image/jpeg content type.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ssh_companywebsite_project:ssh_companywebsite:*:*:*:*:*:*:*:* 2018-05-03 (including)


References to Advisories, Solutions, and Tools