First published: Mon Sep 17 2018(Updated: )
CScms 4.1 allows arbitrary directory deletion via a dir=..\\ substring to plugins\sys\admin\Plugins.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Chshcms Cscms | =4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-17125.
The severity of CVE-2018-17125 is high.
The affected software version is CScms 4.1.
CVE-2018-17125 allows arbitrary directory deletion by using a dir=..\\ substring in the Plugins.php file.
There is currently no fix available for CVE-2018-17125.