Vulnerability Description
In Gxlcms QY v1.0.0713, the upload function in Lib\Lib\Action\Admin\UploadAction.class.php allows remote attackers to execute arbitrary PHP code by first using an Admin-Admin-Configsave request to change the config[upload_class] value from jpg,gif,png,jpeg to jpg,gif,png,jpeg,php and then making an Admin-Upload-Upload request.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gxlcms | Gxlcms Qy | 1.0.0713 |
Related Weaknesses (CWE)
References
- http://www.atksec.com/cve/GxlcmsQY-v1.0.0713-upload-getshell/index.htmlExploitThird Party Advisory
- http://www.atksec.com/cve/GxlcmsQY-v1.0.0713-upload-getshell/index.htmlExploitThird Party Advisory
FAQ
What is CVE-2018-9848?
CVE-2018-9848 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In Gxlcms QY v1.0.0713, the upload function in Lib\Lib\Action\Admin\UploadAction.class.php allows remote attackers to execute arbitrary PHP code by first using an Admin-Admin-Configsave request to cha...
How severe is CVE-2018-9848?
CVE-2018-9848 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-9848?
Check the references section above for vendor advisories and patch information. Affected products include: Gxlcms Gxlcms Qy.