First published: Wed Jan 30 2019(Updated: )
An issue was discovered in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../ to designate an arbitrary directory because of an apps.admincp.php error. This directory can then be deleted via an admincp.php?app=apps&do=uninstall request.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iCMS | =7.0.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-7235.
The severity of CVE-2019-7235 is high (7.5).
CVE-2019-7235 allows directory traversal in idreamsoft iCMS 7.0.13.
The CWE for CVE-2019-7235 is CWE-22.
A fix for CVE-2019-7235 may be available from idreamsoft.