Back to search
CVE-2018-11392
Published: May 29, 2018
Modified: Aug 5, 2024
PUBLISHED
Description
An arbitrary file upload vulnerability in /classes/profile.class.php in Jigowatt "PHP Login & User Management" before 4.1.1, as distributed in the Envato Market, allows any remote authenticated user to upload .php files to the web server via a profile avatar field. This results in arbitrary code execution by requesting the .php file.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://codecanyon.net/item/php-login-user-management/49008
x_refsource_CONFIRM
20180523 PHP Login & User Management <= 4.1.0 - Arbitrary File Upload (CVE-2018-11392)
mailing-list
x_refsource_BUGTRAQ
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now