CVE-2018-13038: Opendesa Opensid

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

OpenSID 18.06-pasca has an Unrestricted File Upload vulnerability via an Attachment Document in the article feature. This vulnerability leads to uploading arbitrary PHP code via a .php filename with the application/pdf Content-Type.

Affected products

  • Opendesa Opensid: version 18.06-pasca only

Published 2018-07-01. Last modified 2026-06-17.