Security Advisory

CVE-2018-10574

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-04-30 20:00:00
Last updated 2024-09-16 17:43:54
Assigner mitre
State PUBLISHED

Description

site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PHP code because the BigTreeStorage class in core/inc/bigtree/apis/storage.php does not prevent uploads of .htaccess files.