CVE-2018-9209 is a critical unauthenticated arbitrary file upload vulnerability affecting FineUploader php-traditional-server versions up to and including 1.2.2. This flaw allows an attacker to upload malicious files without authentication, potentially leading to complete compromise of the affected system (CVSS 9.8). While no public exploits or active exploitation have been observed, and community discussion is minimal, the high severity and ease of exploitation (low attack complexity, no user interaction) warrant immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.2.2CPE matchmatch criteria | cpe:2.3:a:fineuploader:php-traditional-server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.