Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or…
mitre·CWE-184·Published 2018-01-29