CVE-2018-19798

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
02/03/2020
Last modified:
04/03/2020

Description

Fleetco Fleet Maintenance Management (FMM) 1.2 and earlier allows uploading an arbitrary ".php" file with the application/x-php Content-Type to the accidents_add.php?submit=1 URI, as demonstrated by the value_Images_1 field, which leads to remote command execution on the remote server. Any authenticated user can exploit this.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fleetco:fleet_maintenance_management:*:*:*:*:*:*:*:* 1.2 (including)


References to Advisories, Solutions, and Tools