CVE-2018-12494: Path Traversal
Published Jun 15, 2018
·Updated
An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via an admin/cmsTemplate/content.html?path=../ URI.
Affected Software
1 affected component
PublicCMS publiccms=4.0.20180210
Event History
Jun 15, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12494?
The severity of CVE-2018-12494 is medium with a CVSS score of 6.5.
2
How does CVE-2018-12494 affect PublicCMS?
CVE-2018-12494 affects PublicCMS version 4.0.20180210.
3
What is the vulnerability in PublicCMS related to CVE-2018-12494?
The vulnerability in PublicCMS related to CVE-2018-12494 is a Directory Traversal and Arbitrary file read vulnerability.
4
How can an attacker exploit CVE-2018-12494?
An attacker can exploit CVE-2018-12494 by sending a specially crafted request to the admin/cmsTemplate/content.html?path=../ URI, allowing them to read arbitrary files on the system.
5
Is there a fix available for CVE-2018-12494?
Yes, a fix for CVE-2018-12494 is available. It is recommended to upgrade to a version of PublicCMS that is not affected by this vulnerability.