CVE-2018-14441: SSH Companywebsite Project SSH Companywebsite
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. admin/admin/fileUploadAction_fileUpload.action allows arbitrary file upload, as demonstrated by a .jsp file with the image/jpeg content type.
Affected products
- SSH Companywebsite Project SSH Companywebsite: up to and including 2018-05-03
Published 2018-07-20. Last modified 2026-06-17.