First published: Thu Apr 26 2018(Updated: )
mc-admin/post.php in MiniCMS 1.10 allows remote attackers to obtain a directory listing of the top-level directory of the web root via a link that becomes available after posting an article.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
1234n Minicms | =1.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-10423 is medium.
Remote attackers can exploit CVE-2018-10423 by obtaining a directory listing of the top-level directory of the web root via a link that becomes available after posting an article.
The affected software for CVE-2018-10423 is MiniCMS version 1.10.
Yes, there is a fix for CVE-2018-10423. Please refer to the provided reference for more information.
You can find more information about CVE-2018-10423 at the following reference: https://github.com/bg5sbk/MiniCMS/issues/18