CVE-2018-18752

Webiness Inventory 2.3 suffers from an Arbitrary File upload vulnerability via PHP code in the protected/library/ajax/WsSaveToModel.php logo parameter.
Configurations

Configuration 1 (hide)

cpe:2.3:a:webiness_project:webiness_inventory:2.3:*:*:*:*:*:*:*

History

21 Nov 2024, 03:56

Type Values Removed Values Added
References () https://packetstormsecurity.com/files/149982/Webiness-Inventory-2.9-Shell-Upload.html - Exploit, VDB Entry, Third Party Advisory () https://packetstormsecurity.com/files/149982/Webiness-Inventory-2.9-Shell-Upload.html - Exploit, Third Party Advisory, VDB Entry

Information

Published : 2018-10-29 12:29

Updated : 2024-11-21 03:56


NVD link : CVE-2018-18752

Mitre link : CVE-2018-18752

CVE.ORG link : CVE-2018-18752


JSON object : View

Products Affected

webiness_project

  • webiness_inventory
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type