First published: Thu Apr 26 2018(Updated: )
mc-admin/post-edit.php in MiniCMS 1.10 allows full path disclosure via a modified id field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
1234n Minicms | =1.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10424 is a vulnerability in MiniCMS 1.10 that allows full path disclosure via a modified id field.
CVE-2018-10424 has a severity level of medium (2.7).
CVE-2018-10424 affects MiniCMS version 1.10.
To fix CVE-2018-10424 in MiniCMS, please update to the latest version of MiniCMS.
You can find more information about CVE-2018-10424 in the GitHub issue: https://github.com/bg5sbk/MiniCMS/issues/18