CVE-2018-17139 is a critical arbitrary file upload vulnerability in UltimatePOS 2.5, allowing authenticated attackers to achieve remote code execution by uploading malicious PHP files disguised as JPEG images to the /products URI. This vulnerability carries a high CVSS score of 8.8, indicating a severe risk due to its low attack complexity and potential for complete compromise of confidentiality, integrity, and availability. Despite its high severity, there is no known public exploit code (Metasploit, Nuclei, ExploitDB), and it has not been added to CISA's KEV catalog, suggesting limited active exploitation or community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.5CPE matchmatch criteria | cpe:2.3:a:ultimatefosters:ultimatepos:2.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.