Medium severity6.5NVD Advisory· Published Jul 3, 2018· Updated Jun 17, 2026
CVE-2018-13122
CVE-2018-13122
Description
onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to delete arbitrary files via the Delete File(s) screen, as demonstrated by a ?i=var/www/html/&f=123.php&p=edit&p=deletefile URI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<=2017-10-08+ 1 more
- (no CPE)range: <=2017-10-08
- cpe:2.3:a:onefilecms:onefilecms:*:*:*:*:*:*:*:*range: <=3.6.13
- Range: through 2017-10-08
Patches
Vulnerability mechanics
References
1- github.com/Self-Evident/OneFileCMS/issues/49nvdThird Party Advisory
News mentions
0No linked articles in our index yet.