Vulnerabilities
Vulnerable Software
Pivotx:  >> Pivotx  >> 2.3.11  Security Vulnerabilities
lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via an upload of a .php file.
CVSS Score
7.2
EPSS Score
0.006
Published
2017-10-02
The smarty_self function in modules/module_smarty.php in PivotX 2.3.11 mishandles the URI, allowing XSS via vectors involving quotes in the self Smarty tag.
CVSS Score
6.1
EPSS Score
0.002
Published
2017-06-06
PivotX 2.3.11 allows remote authenticated users to execute arbitrary PHP code via vectors involving an upload of a .htaccess file.
CVSS Score
8.8
EPSS Score
0.006
Published
2017-05-31
PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (such as .jpg) and then invoking the duplicate function to change to the .php extension.
CVSS Score
8.8
EPSS Score
0.008
Published
2017-04-07


Contact Us

Shodan ® - All rights reserved