CVE-2018-6880: Medium severity Phome Empirecms vulnerability
Published Feb 12, 2018
·Updated
EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/connect.php.
Affected Software
1 affected component
Phome Empirecms>=6.6<=7.2
Event History
Feb 12, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Data Sourced
via NVD·03:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6880?
CVE-2018-6880 has been assigned a medium severity level due to its impact on information disclosure.
2
How can I fix CVE-2018-6880?
To fix CVE-2018-6880, upgrade EmpireCMS to version 7.3 or later to eliminate the vulnerability.
3
What types of attacks are possible with CVE-2018-6880?
CVE-2018-6880 allows remote attackers to perform path disclosure attacks, potentially revealing sensitive information about the server's file system.
4
Which versions of EmpireCMS are affected by CVE-2018-6880?
CVE-2018-6880 affects EmpireCMS versions 6.6 through 7.2.
5
Is there any workaround for CVE-2018-6880?
As a workaround for CVE-2018-6880, it is advisable to restrict access to the affected 'class/connect.php' file until an upgrade can be applied.