First published: Thu Apr 25 2019(Updated: )
core/classes/db_backup.php in Gila CMS 1.10.1 allows admin/db_backup?download= absolute path traversal to read arbitrary files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tina Tinacms | =1.10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-11515.
The severity of CVE-2019-11515 is medium.
The affected software version of CVE-2019-11515 is Gilacms Gila Cms 1.10.1.
CVE-2019-11515 is a vulnerability in Gila CMS 1.10.1 that allows absolute path traversal to read arbitrary files.
Yes, please refer to the vendor's website or contact the vendor for a fix for CVE-2019-11515.