CVE-2015-7773
Last modified
CVE-2015-7773 is a vulnerability of currently unknown severity. Unrestricted file upload vulnerability in the Panel component in Bastian Allgeier Kirby before 2.1.2 allows remote authenticated users to execute arbitrary PHP code by uploading a file that lacks an extension, and then renaming this file to have a .php extension.. EPSS estimates a 1.26% chance of exploitation in the next 30 days.
Description
Unrestricted file upload vulnerability in the Panel component in Bastian Allgeier Kirby before 2.1.2 allows remote authenticated users to execute arbitrary PHP code by uploading a file that lacks an extension, and then renaming this file to have a .php extension.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bastian Allgeier | Kirby | <= 2.1.1 |
References
- http://getkirby.com/changelog/kirby-2-1-2Patch, Vendor Advisory
- http://jvn.jp/en/jp/JVN34780384/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000182Vendor Advisory
- http://getkirby.com/changelog/kirby-2-1-2Patch, Vendor Advisory
- http://jvn.jp/en/jp/JVN34780384/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000182Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-7773?
How severe is CVE-2015-7773?
How do I fix CVE-2015-7773?
Are you affected by CVE-2015-7773?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
