CVE-2018-6383 EXPLOIT
8.8
HIGH · CVSS 3.1 · EPSS 13.5% (pctl 96)
Patch early
A public exploit exists.
Description
Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extension, which allows remote authenticated Admins or Editors to execute arbitrary PHP code by uploading a file, a different vulnerability than CVE-2017-18048.
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 13.5% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-184 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-01-29 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| monstra | monstra |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Monstra CMS 3.0.4 - Remote Code Execution (Authenticated) | 2021-06-04 |
References
- http://packetstormsecurity.com/files/162968/Monstra-CMS-3.0.4-Remote-Code-Execution.html
- https://github.com/Hacker5preme/Exploits/tree/main/CVE-2018-6383-Exploit
- https://github.com/monstra-cms/monstra/issues/429
- http://packetstormsecurity.com/files/162968/Monstra-CMS-3.0.4-Remote-Code-Execution.html
- https://github.com/Hacker5preme/Exploits/tree/main/CVE-2018-6383-Exploit
- https://github.com/monstra-cms/monstra/issues/429
→ the Explorer · watch your stack · NVD