Vulnerability Description
PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (such as .jpg) and then invoking the duplicate function to change to the .php extension.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pivotx | Pivotx | 2.3.11 |
Related Weaknesses (CWE)
References
- https://gist.github.com/X1nda/749b6aac6e080624d9f8ec81321335dfExploitThird Party Advisory
- https://gist.github.com/X1nda/749b6aac6e080624d9f8ec81321335dfExploitThird Party Advisory
FAQ
What is CVE-2017-7570?
CVE-2017-7570 is a vulnerability with a CVSS score of 8.8 (HIGH). PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (such as .jpg) and then invoking the duplicate function to cha...
How severe is CVE-2017-7570?
CVE-2017-7570 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7570?
Check the references section above for vendor advisories and patch information. Affected products include: Pivotx Pivotx.