PT-2018-14713 · Minicms · Minicms

Published

2018-11-01

·

Updated

2018-12-03

·

CVE-2018-18892

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MiniCMS version 1.10
Description The issue allows execution of arbitrary PHP code via the sitename parameter in the install.php endpoint, affecting the site name field in mc conf.php.
Recommendations For MiniCMS version 1.10, consider restricting access to the install.php endpoint until a patch is available, and avoid using the sitename parameter to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-18892

Affected Products

Minicms