CVE-2023-26775

HIGH EXPLOITED

Monitorr 1.7.6 - Remote Code Execution via File Upload to upload.php

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2023-26775 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

File Upload vulnerability found in Monitorr v.1.7.6 allows a remote attacker t oexecute arbitrary code via a crafted file upload to the assets/php/upload.php endpoint.

Scores

CVSS v3 7.8
EPSS 0.4937
EPSS Percentile 98.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2024-02-10
CWE
CWE-434
Status published
Products (1)
monitorr/monitorr 1.7.6m
Published Apr 04, 2023
Tracked Since Feb 18, 2026