VYPR

Bagecms

by Bagecms

CVEs (1)

  • CVE-2018-18257Oct 11, 2018
    risk 0.00cvss epss 0.00

    An issue was discovered in BageCMS 3.1.3. An attacker can delete any files and folders on the web server via an index.php?r=admini/template/batch&command=deleteFile&fileName= or index.php?r=admini/template/batch&command=deleteFolder&folderName=../ directory traversal URI.