High severity7.5NVD Advisory· Published Apr 11, 2023· Updated Jun 17, 2026
CVE-2023-27179
CVE-2023-27179
Description
GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:gdidees:gdidees_cms:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:gdidees:gdidees_cms:*:*:*:*:*:*:*:*range: <=3.9.1
- (no CPE)range: <=3.9.1
- GDidees/CMSdescription
Patches
Vulnerability mechanics
References
5- gist.github.com/Hadi999/516aa25b953b0cba57089a0c11b1305bnvdThird Party Advisory
- knowledge-base.secureflag.com/vulnerabilities/unrestricted_file_download/unrestricted_file_download_vulnerability.htmlnvdThird Party Advisory
- www.gdidees.eu/cms-1-0.htmlnvdProduct
- packetstormsecurity.com/files/171894/GDidees-CMS-3.9.1-Local-File-Disclosure-Directory-Traversal.htmlnvd
- packetstorm.news/files/id/171894nvd
News mentions
0No linked articles in our index yet.