CVE-2017-10665: Phpgrid

High severity, CVSS 7.8. EPSS: 3.2% chance of exploitation in the next 30 days.

Directory traversal vulnerability in ajaxfileupload.php in Kayson Group Ltd. phpGrid before 7.2.5 allows remote attackers to execute arbitrary code by uploading a crafted file with a .. (dot dot) in the file name.

Affected products

  • Phpgrid Phpgrid: up to and including 7.2

Published 2017-08-18. Last modified 2026-06-17.