CVE-2018-16288: Infoleak
Published Sep 14, 2018
·Updated
LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.
Affected Software
1 affected component
LG SuperSign CMS=2.5
Event History
Sep 14, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16288?
The severity of CVE-2018-16288 is high with a value of 8.6.
2
How does CVE-2018-16288 affect LG SuperSign CMS?
CVE-2018-16288 allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs in LG SuperSign CMS.
3
What is the affected software for CVE-2018-16288?
The affected software for CVE-2018-16288 is LG SuperSign CMS version 2.5.
4
How can I fix CVE-2018-16288?
To fix CVE-2018-16288 on LG SuperSign CMS, update to a version that is not affected by this vulnerability.
5
Where can I find more information about CVE-2018-16288?
For more information about CVE-2018-16288, you can refer to the following references: [link1](http://mamaquieroserpentester.blogspot.com/2018/09/multiple-vulnerabilities-in-lg.html), [link2](https://www.exploit-db.com/exploits/45440/).