Unrated severityNVD Advisory· Published Oct 11, 2018· Updated Aug 5, 2024
CVE-2018-18257
CVE-2018-18257
Description
An issue was discovered in BageCMS 3.1.3. An attacker can delete any files and folders on the web server via an index.php?r=admini/template/batch&command=deleteFile&fileName= or index.php?r=admini/template/batch&command=deleteFolder&folderName=../ directory traversal URI.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/rakjong/vuln/blob/master/Bagecms_vuln_2.pdfmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.