First published: Thu Nov 01 2018(Updated: )
MiniCMS 1.10 allows file deletion via /mc-admin/post.php?state=delete&delete= because the authentication check occurs too late.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
1234n Minicms | =1.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-18891 is high, with a severity value of 7.5.
MiniCMS version 1.10 is affected by CVE-2018-18891.
CVE-2018-18891 allows file deletion through the /mc-admin/post.php?state=delete&delete= endpoint.
The authentication check in CVE-2018-18891 occurs too late, allowing the file deletion vulnerability to be exploited.
To fix CVE-2018-18891, update MiniCMS to a version that includes the necessary fixes for the authentication vulnerability.