CVE-2018-16974 is a critical PHP code execution vulnerability affecting Elefant CMS versions prior to 2.0.7. An unauthenticated attacker can exploit this by first removing the .htaccess file via the file manager API, then uploading a malicious PHP file with a specially crafted filename to bypass blacklist restrictions. This allows for complete compromise of the affected system, as reflected by its CVSS score of 9.8 (Critical). While no public exploit code or active exploitation has been observed, and community discussion is minimal, the high severity and ease of exploitation warrant immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.7CPE matchmatch criteria | cpe:2.3:a:elefantcms:elefant:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.