216.73.216.6

CVE-2013-10054

· Published 04/08/2025 18:15 · Modified 05/08/2025 16:15

Labels: CVE-2013-10054 2025-08-04CVE-2013-10054CWE-434[email protected]

Essential information

Published
04/08/2025 18:15
Modified
05/08/2025 16:15
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An unauthenticated arbitrary file upload vulnerability exists in LibrettoCMS version 1.1.7 (and possibly earlier) contains an unauthenticated arbitrary file upload vulnerability in its File Manager plugin. The upload handler located at adm/ui/js/ckeditor/plugins/pgrfilemanager/php/upload.php fails to properly validate file extensions, allowing attackers to upload files with misleading extensions and subsequently rename them to executable .php scripts. This enables remote code execution on the server without authentication.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
libretto / librettocms cpe:2.3:a:libretto:librettocms:*:*:*:*:*:*:*:*

References