CVE-2018-15698: Infoleak
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on the file system when providing the full path to loginimage.cgi.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15698?
CVE-2018-15698 is a vulnerability in ASUSTOR Data Master 3.1.5 and below that allows authenticated remote non-administrative users to read any file on the file system when providing the full path to loginimage.cgi.
How does CVE-2018-15698 impact ASUSTOR Data Master?
CVE-2018-15698 allows authenticated remote non-administrative users to read any file on the ASUSTOR Data Master file system.
What is the severity of CVE-2018-15698?
CVE-2018-15698 has a severity level of medium, with a severity value of 6.5.
How can I fix CVE-2018-15698?
To fix CVE-2018-15698, it is recommended to update ASUSTOR Data Master to version 3.1.6 or later.
Where can I find more information about CVE-2018-15698?
More information about CVE-2018-15698 can be found at the following link: [https://www.tenable.com/security/research/tra-2018-22](https://www.tenable.com/security/research/tra-2018-22)