CVE-2018-9037

HIGH

Monstra - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

Monstra CMS 3.0.4 allows remote code execution via an upload_file request for a .zip file, which is automatically extracted and may contain .php files.

References (2)

Core 2
Core References
Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44621/
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/monstra-cms/monstra/issues/433

Scores

CVSS v3 8.8
EPSS 0.0203
EPSS Percentile 83.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
monstra/monstra 3.0.4
Published Apr 10, 2018
Tracked Since Feb 18, 2026