CVE-2018-7479: Medium severity YzmCMS YzmCMS vulnerability
Published Feb 26, 2018
·Updated
YzmCMS 3.6 allows remote attackers to discover the full path via a direct request to application/install/templates/s1.php.
Affected Software
1 affected component
YzmCMS YzmCMS=3.6
Event History
Feb 26, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Data Sourced
via NVD·03:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-7479?
CVE-2018-7479 is rated as a medium severity vulnerability due to its ability to disclose sensitive path information.
2
How do I fix CVE-2018-7479?
To fix CVE-2018-7479, it's recommended to restrict access to the installation files or update to a patched version of YzmCMS.
3
What type of vulnerability is CVE-2018-7479?
CVE-2018-7479 is a path disclosure vulnerability that allows attackers to obtain the full directory path of the application.
4
Can CVE-2018-7479 be exploited remotely?
Yes, CVE-2018-7479 can be exploited remotely by attackers who send a direct request to the vulnerable file.
5
Which versions of Yzmcms are affected by CVE-2018-7479?
CVE-2018-7479 specifically affects Yzmcms version 3.6.