First published: Fri Jun 15 2018(Updated: )
An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via an admin/cmsTemplate/content.html?path=../ URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
sanluan PublicCMS | =4.0.20180210 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-12494 is medium with a CVSS score of 6.5.
CVE-2018-12494 affects PublicCMS version 4.0.20180210.
The vulnerability in PublicCMS related to CVE-2018-12494 is a Directory Traversal and Arbitrary file read vulnerability.
An attacker can exploit CVE-2018-12494 by sending a specially crafted request to the admin/cmsTemplate/content.html?path=../ URI, allowing them to read arbitrary files on the system.
Yes, a fix for CVE-2018-12494 is available. It is recommended to upgrade to a version of PublicCMS that is not affected by this vulnerability.