AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-20129

HIGH · CVSS 8.8 EPSS 8.23%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-12-13 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2018-20129
Severity
HIGH
CVSS
8.8
EPSS
8.23%

Original NVD Description

An issue was discovered in DedeCMS V5.7 SP2. uploads/include/dialog/select_images_post.php allows remote attackers to upload and execute arbitrary PHP code via a double extension and a modified ".php" substring, in conjunction with the image/jpeg content type, as demonstrated by the filename=1.jpg.p*hp value.