First published: Tue Apr 11 2023(Updated: )
GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GDidees CMS | <=3.9.1 | |
<=3.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27179 refers to an arbitrary file download vulnerability in GDidees CMS v3.9.1 and lower.
The vulnerability arises due to improper handling of the filename parameter in the /_admin/imgdownload.php file of GDidees CMS.
CVE-2023-27179 has a severity score of 7.5 (high).
Update GDidees CMS to version 3.9.2 or higher to prevent the arbitrary file download vulnerability.
More information about CVE-2023-27179 can be found at the following references: [link1], [link2], [link3].