CVE-2018-18831: Path Traversal
An issue was discovered in com\mingsoft\cms\action\GeneraterAction.java in MCMS 4.6.5. An attacker can write a .jsp file (in the position parameter) to an arbitrary directory via a ../ Directory Traversal in the url parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-18831?
CVE-2018-18831 is a vulnerability discovered in MCMS 4.6.5 that allows an attacker to write a .jsp file to an arbitrary directory through a ../ Directory Traversal in the url parameter.
How can an attacker exploit CVE-2018-18831?
An attacker can exploit CVE-2018-18831 by writing a .jsp file in the position parameter and exploiting the ../ Directory Traversal vulnerability in the url parameter.
What is the severity of CVE-2018-18831?
The severity of CVE-2018-18831 is high, with a CVSS score of 7.5.
How do I fix CVE-2018-18831?
To fix CVE-2018-18831, it is recommended to update MCMS to a version that addresses the vulnerability.
Where can I find more information about CVE-2018-18831?
You can find more information about CVE-2018-18831 at the following URL: https://gitee.com/mingSoft/MCMS/issues/IO0K0