CVE-2013-10055 describes a critical unauthenticated arbitrary file upload vulnerability in Havalite CMS version 1.1.7 and potentially earlier, specifically within the upload.php script. This flaw allows remote attackers to upload malicious PHP files due to inadequate file extension validation and missing authentication checks. Successful exploitation leads to remote code execution by accessing the uploaded file directly. The vulnerability carries a CVSS 4.0 score of 9.3 (CRITICAL), indicating a severe risk with a network attack vector, low attack complexity, and no required privileges or user interaction. The potential impact includes high confidentiality, integrity, and availability compromise. While not listed on CISA's KEV catalog, a Metasploit module exists for this vulnerability, confirming readily available exploit code. Community discussion is notably high, with 18 mentions, suggesting significant awareness and potential interest among security researchers and threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Havalite CMS | Havalite CMS | 1.1.7CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.