VYPR
Unrated severityNVD Advisory· Published Nov 27, 2018· Updated Aug 5, 2024

CVE-2018-17936

CVE-2018-17936

Description

NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files to the server, which could allow remote code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NUUO CMS versions 3.3 and prior allow arbitrary file upload that can modify configuration files, leading to remote code execution.

Vulnerability

NUUO CMS versions 3.3 and prior [1] include an unrestricted upload of files with dangerous types. The application fails to properly validate uploaded files, allowing an attacker to upload arbitrary files that can modify or overwrite configuration files on the server. This vulnerability is cataloged as path traversal and unrestricted file upload and can be exploited remotely without authentication [1].

Exploitation

An attacker can exploit this vulnerability by sending a crafted HTTP request containing a malicious file (e.g., a PHP script) to the NUUO CMS server. The attacker does not need prior authentication or special privileges. The uploaded file can then be used to overwrite configuration files or execute arbitrary code. The vulnerability is rated as requiring low skill level to exploit [1].

Impact

Successful exploitation allows an attacker to achieve remote code execution with the privileges of the web server. This can lead to full compromise of the affected system, including disclosure of sensitive information, modification of data, or disruption of service. The CVSS v3 base score is 9.8 (Critical), with vectors AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [1].

Mitigation

As of the advisory date (November 27, 2018), the vendor had not released a fix. Users are advised to apply defense-in-depth measures, limit network access to the CMS, and monitor for suspicious activity. The advisory recommends contacting NUUO for an update or patch [1]. No CISA KEV listing was identified for this CVE.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.