First published: Wed Sep 26 2018(Updated: )
SeaCMS 6.64 and 7.2 allows remote attackers to delete arbitrary files via the filedir parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Seacms Seacms | =6.64 | |
Seacms Seacms | =7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17365 is a vulnerability in SeaCMS 6.64 and 7.2 that allows remote attackers to delete arbitrary files via the filedir parameter.
CVE-2018-17365 has a severity rating of 7.5, which is considered high.
SeaCMS versions 6.64 and 7.2 are affected by CVE-2018-17365.
The file deletion vulnerability in SeaCMS can be exploited by sending malicious requests with a specially crafted filedir parameter.
Yes, you can find more information about CVE-2018-17365 at the following references: http://blog.51cto.com/13770310/2177226 and https://github.com/sfh320/seacms/issues/1