Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-13980

Опубликовано: 16 июл. 2018
Источник: nvd
CVSS3: 5.5
CVSS2: 2.1
EPSS Средний

Описание

The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclosure if the plugin "filebrowser" is installed, because of assets/php/filebrowser/filebrowser.main.php?file=../ directory traversal.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zeta-producer:zeta_producer:*:*:*:*:*:*:*:*
Версия до 14.2.1 (исключая)

EPSS

Процентиль: 93%
0.11342
Средний

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.5
github
больше 3 лет назад

The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclosure if the plugin "filebrowser" is installed, because of assets/php/filebrowser/filebrowser.main.php?file=../ directory traversal.

EPSS

Процентиль: 93%
0.11342
Средний

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-22