First published: Wed Jan 30 2019(Updated: )
An issue was discovered in idreamsoft iCMS 7.0.13. editor/editor.admincp.php allows admincp.php?app=editor&do=fileManager dir=../ Directory Traversal.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iCMS | =7.0.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-7236 is high with a CVSS score of 7.5.
CVE-2019-7236 affects idreamsoft iCMS version 7.0.13.
CVE-2019-7236 is a directory traversal vulnerability.
CVE-2019-7236 can be exploited by manipulating the dir parameter in the admincp.php?app=editor&do=fileManager URL.
Yes, updating to a patched version of idreamsoft iCMS will fix CVE-2019-7236.