Vulnerability Description
Webiness Inventory 2.3 suffers from an Arbitrary File upload vulnerability via PHP code in the protected/library/ajax/WsSaveToModel.php logo parameter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Webiness Project | Webiness Inventory | 2.3 |
Related Weaknesses (CWE)
References
- https://packetstormsecurity.com/files/149982/Webiness-Inventory-2.9-Shell-UploadExploitThird Party AdvisoryVDB Entry
- https://packetstormsecurity.com/files/149982/Webiness-Inventory-2.9-Shell-UploadExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2018-18752?
CVE-2018-18752 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Webiness Inventory 2.3 suffers from an Arbitrary File upload vulnerability via PHP code in the protected/library/ajax/WsSaveToModel.php logo parameter.
How severe is CVE-2018-18752?
CVE-2018-18752 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-18752?
Check the references section above for vendor advisories and patch information. Affected products include: Webiness Project Webiness Inventory.