PT-2018-14918 · Laoban · Laobancms

Published

2018-11-17

·

Updated

2020-05-07

·

CVE-2018-19328

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LAOBANCMS version 2.0
Description The issue allows for directory traversal via the riqi parameter in the install/mysql hy.php endpoint.
Recommendations For LAOBANCMS version 2.0, as a temporary workaround, consider restricting access to the install/mysql hy.php endpoint until a patch is available. Avoid using the riqi parameter in this endpoint to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-19328

Affected Products

Laobancms