CVE-2017-18048: Monstra
High severity, CVSS 8.8. EPSS: 63.4% chance of exploitation in the next 30 days.
Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lowercase) is blocked but .PHP (uppercase) is not.
Affected products
- Monstra Monstra: version 3.0.4 only
Published 2018-01-23. Last modified 2026-06-17.