Unrated severityNVD Advisory· Published Nov 1, 2018· Updated Sep 16, 2024
CVE-2018-18890
CVE-2018-18890
Description
MiniCMS 1.10 allows full path disclosure via /mc-admin/post.php?state=delete&delete= with an invalid filename.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/AvaterXXX/MiniCms/blob/master/Authentication%20and%20Information%20Exposure.mdmitrex_refsource_MISC
- www.patec.cn/newsshow.phpmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.