CVE-2017-14958

Publication date

2017-10-01 15:00:00

Family

mitre

State

PUBLISHED

Description

lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via an upload of a .php file.