VYPR
High severity7.2NVD Advisory· Published Feb 26, 2018· Updated Jun 17, 2026

CVE-2018-7486

CVE-2018-7486

Description

Blue River Mura CMS before v7.0.7029 supports inline function calls with an [m] tag and [/m] end tag, without proper restrictions on file types or pathnames, which allows remote attackers to execute arbitrary code via an [m]$.dspinclude("../pathname/executable.jpeg")[/m] approach, where executable.jpeg contains ColdFusion Markup Language code. This can be exploited in conjunction with a CKFinder feature that allows file upload.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Blueriver/Muracmsinferred2 versions
    <7.0.7029+ 1 more
    • (no CPE)range: <7.0.7029
    • cpe:2.3:a:blueriver:muracms:*:*:*:*:*:*:*:*range: <7.0.7029
  • Range: <7.0.7029

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.