Vulnerability Description
PHPOK 4.9.032 has an arbitrary file upload vulnerability in the import_f function in framework/admin/modulec_control.php, as demonstrated by uploading a .php file within a .php.zip archive, a similar issue to CVE-2018-8944.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpok | Phpok | 4.9.032 |
Related Weaknesses (CWE)
References
- https://github.com/SukaraLin/php_code_audit_project/blob/master/phpok/Phpok%204.ExploitThird Party Advisory
- https://github.com/SukaraLin/php_code_audit_project/blob/master/phpok/Phpok%204.ExploitThird Party Advisory
FAQ
What is CVE-2018-12491?
CVE-2018-12491 is a vulnerability with a CVSS score of 9.8 (CRITICAL). PHPOK 4.9.032 has an arbitrary file upload vulnerability in the import_f function in framework/admin/modulec_control.php, as demonstrated by uploading a .php file within a .php.zip archive, a similar ...
How severe is CVE-2018-12491?
CVE-2018-12491 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-12491?
Check the references section above for vendor advisories and patch information. Affected products include: Phpok Phpok.