Vulnerabilities (CVE)

Filtered by vendor Pivotx Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-14958 1 Pivotx 1 Pivotx 2017-10-06 6.5 MEDIUM 7.2 HIGH
lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via an upload of a .php file.
CVE-2017-8402 1 Pivotx 1 Pivotx 2017-06-08 6.5 MEDIUM 8.8 HIGH
PivotX 2.3.11 allows remote authenticated users to execute arbitrary PHP code via vectors involving an upload of a .htaccess file.
CVE-2017-7570 1 Pivotx 1 Pivotx 2017-04-13 6.5 MEDIUM 8.8 HIGH
PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (such as .jpg) and then invoking the duplicate function to change to the .php extension.