VYPR
Unrated severityNVD Advisory· Published Nov 27, 2018· Updated Aug 5, 2024

CVE-2018-17934

CVE-2018-17934

Description

NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be resolved outside the intended directory. This could allow an attacker to impersonate a legitimate user, obtain restricted information, or execute arbitrary code.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NUUO CMS versions 3.3 and prior contain a path traversal vulnerability allowing remote attackers to obtain restricted information or execute arbitrary code.

Vulnerability

NUUO CMS versions 3.3 and prior (including versions 3.1 and earlier) contain a path traversal vulnerability [1]. The application allows external input to construct a pathname that can be resolved outside the intended directory, enabling an attacker to read or write files outside the web root or application boundaries [1].

Exploitation

An attacker can exploit this vulnerability remotely without authentication or user interaction [1]. The CVSS v3 vector string (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates network-based exploitation with low attack complexity [1]. The attacker sends crafted HTTP requests containing path traversal sequences (e.g., ../) to traverse directories and access or manipulate files outside the intended scope [1].

Impact

Successful exploitation could allow an attacker to impersonate a legitimate user, obtain restricted information, or execute arbitrary code [1]. The CISA advisory notes that these vulnerabilities could result in arbitrary remote code execution [1]. The confidentiality, integrity, and availability impacts are all rated as high [1].

Mitigation

NUUO CMS version 3.1 and prior were initially affected; the updated advisory extended the affected versions to 3.3 and prior [1]. As of the advisory publication date (October 11, 2018, updated November 27, 2018), no fix or workaround is explicitly mentioned in the available references [1]. Users should contact NUUO for updated versions or apply appropriate input validation and directory restrictions as a defense [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.