VYPR
High severity7.5NVD Advisory· Published Oct 18, 2018· Updated Jun 17, 2026

CVE-2018-18487

CVE-2018-18487

Description

In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, the database backup filename generation uses mt_rand() unsafely, resulting in predictable database backup file locations.

Affected products

3
  • Gxlcms/Gxlcmsinferred3 versions
    = 2.0+ 2 more
    • (no CPE)range: = 2.0
    • cpe:2.3:a:gxlcms:gxlcms:2.0:*:*:*:*:*:*:*
    • (no CPE)range: = 2.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.