PT-2018-11285 · Greencms · Greencms

Vr_System

·

Published

2018-06-20

·

Updated

2018-08-10

·

CVE-2018-12604

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GreenCMS version 2.3.0603
Description The issue allows remote attackers to obtain sensitive information by making a direct request for log files, specifically Data/Log/year month day.log.
Recommendations For GreenCMS version 2.3.0603, consider restricting access to the log files, specifically the Data/Log/year month day.log, to prevent unauthorized access to sensitive information.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-12604

Affected Products

Greencms