Security Advisory

CVE-2018-18888

9.8
CRITICAL

Vulnerability Description

An issue was discovered in laravelCMS through 2018-04-02. \app\Http\Controllers\Backend\ProfileController.php allows upload of arbitrary PHP files because the file extension is not properly checked and uploaded files are not properly renamed.
Published Date November 1, 2018
Official Source NIST NVD Advisory