VYPR
High severity7.5NVD Advisory· Published Oct 1, 2018· Updated Jun 17, 2026

CVE-2018-17837

CVE-2018-17837

Description

An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file deletion is possible via a /console/file/manage.php?type=action&action=delete&path=c%3A%2F substring.

Affected products

2
  • Jtbc/Jtbcinferred2 versions
    <=3.0.1.6+ 1 more
    • (no CPE)range: <=3.0.1.6
    • (no CPE)range: =3.0.1.6

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.