High severity8.8NVD Advisory· Published Apr 7, 2017· Updated May 13, 2026
CVE-2017-7570
CVE-2017-7570
Description
PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (such as .jpg) and then invoking the duplicate function to change to the .php extension.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- gist.github.com/X1nda/749b6aac6e080624d9f8ec81321335dfnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.