CRITICAL

CVE-2018-13981

CVSS v3

9.8

CRITICAL

EPSS Score

36.7%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code execution due to a default component that permits arbitrary upload of PHP files, because the formmailer widget blocks .php files but not .php5 or .phtml files. This is related to /assets/php/formmailer/SendEmail.php and /assets/php/formmailer/functions.php.

Technical details

Published
7/16/2018

Frequently asked questions

What is CVE-2018-13981?

The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code execution due to a default component that permits arbitrary upload of PHP files, because the formmailer widget blocks .php files but not .php5 or .phtml files. This is related to /assets/php/formmailer/SendEmail.php and /assets/php/formmailer/functions.php.

Is CVE-2018-13981 actively exploited?

Active exploitation of CVE-2018-13981 has not been confirmed. The EPSS score is 36.7%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2018-13981?

CVE-2018-13981 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2018-13981 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.