CVE-2018-18771

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
29/10/2018
Last modified:
11/12/2018

Description

An issue was discovered in LuLu CMS through 2015-05-14. backend\modules\filemanager\controllers\DefaultController.php allows arbitrary file upload by entering a filename, directory name, and PHP code into the three text input fields.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lulucms:lulu_cms:*:*:*:*:*:*:*:* 2015-05-14 (including)


References to Advisories, Solutions, and Tools