CVE-2018-13038: Opendesa Opensid
Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.
OpenSID 18.06-pasca has an Unrestricted File Upload vulnerability via an Attachment Document in the article feature. This vulnerability leads to uploading arbitrary PHP code via a .php filename with the application/pdf Content-Type.
Affected products
- Opendesa Opensid: version 18.06-pasca only
Published 2018-07-01. Last modified 2026-06-17.