Vulnerabilities > Pescms > Pescms Team > Critical

DATE CVE VULNERABILITY TITLE RISK
2018-09-03 CVE-2018-16370 Unrestricted Upload of File with Dangerous Type vulnerability in Pescms Team 2.2.1
In PESCMS Team 2.2.1, attackers may upload and execute arbitrary PHP code through /Public/?g=Team&m=Setting&a=upgrade by placing a .php file in a ZIP archive.
network
low complexity
pescms CWE-434
critical
9.8