CVE-2018-17139
UltimatePOS 2.5 allows users to upload arbitrary files, which leads to remote command execution by posting to a /products URI with PHP code in a .php file with the image/jpeg content type.
- Affected products
- Ultimatepos
- Ultimatefosters Ultimatepos
- = 2.5
- Fix
- Available
- CVSS 3.0
- 8.8 HIGH
- EPSS
- 2.7% (85th percentile)
- Weakness
- CWE-434
- NVD status
- Modified
- Published
- 2018-09-17
CVE-2018-17139 at NVD
No indexed exploits for CVE-2018-17139 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2018-17139 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.