PT-2018-11216 · Publiccms · Publiccms

Jearyorg

·

Published

2018-06-15

·

Updated

2019-03-18

·

CVE-2018-12494

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PublicCMS version 4.0.20180210
Description An issue was discovered that allows for "Directory Traversal" and "Arbitrary file read" via the "/admin/cmsTemplate/content.html" API endpoint with a path variable set to ../.
Recommendations For PublicCMS version 4.0.20180210, as a temporary workaround, consider restricting access to the /admin/cmsTemplate/content.html API endpoint until a patch is available. Avoid using the path variable in this endpoint with relative paths that could lead to directory traversal.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-12494

Affected Products

Publiccms