CVSS v3
7.2
HIGH
EPSS Score
14.5%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filename, because plugins\\box\\filesmanager\\filesmanager.admin.php mishandles the forbidden_types variable.
Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filename, because plugins\\box\\filesmanager\\filesmanager.admin.php mishandles the forbidden_types variable.
Active exploitation of CVE-2018-17418 has not been confirmed. The EPSS score is 14.5%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2018-17418 has a CVSS v3 base score of 7.2 (HIGH severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).