← Vulnerability feed

Vulnerability record · CVE-2018-9038 · published 10 April 2018

CVE-2018-9038: Monstra path traversal vulnerability

Monstra · Monstra

Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request.

6.5 CVSS 3.0 Medium EPSS 9.3% · top 4.8% CWE-22 · Path traversal
6.5CVSS 3.0 base score, v2 5.5
9.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-9038 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-40940Monstra unrestricted file upload vulnerabilityMonstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.EPSS 1.6%9.8CVE-2021-36548Monstra unrestricted file upload vulnerabilityA remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows a…EPSS 3.3%9.8CVE-2020-25414Monstra inclusion from untrusted sphere vulnerabilityA local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitrary PHP c…EPSS 2.0%8.8CVE-2020-13384Monstra unrestricted file upload vulnerabilityMonstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because, for example…EPSS 2.5%8.8CVE-2018-16608Monstra insecure direct object reference vulnerabilityIn Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/index.php?id=users&action=edit&u…EPSS 1.2%8.8CVE-2018-9037Monstra unrestricted file upload vulnerabilityMonstra CMS 3.0.4 allows remote code execution via an upload_file request for a .zip file, which is automatically extracted and may contain .php file…EPSS 2.8%8.8CVE-2018-6383Monstra vulnerabilityMonstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .phar extensi…EPSS 13%8.8CVE-2017-18048Monstra CMS case-sensitive extension check allows arbitrary file upload RCEMonstra CMS 3.0.4 blocks the lowercase .php extension on uploads but not the uppercase .PHP, so an authenticated user can upload a PHP file that the …EPSS 63%analysed

Source: NIST National Vulnerability Database (record CVE-2018-9038), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.