PT-2024-12517 · Modern Campus · Modern Campus - Omni Cms

Published

2024-06-13

·

Updated

2024-08-14

·

CVE-2023-35860

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Modern Campus - Omni CMS version 2023.1
Description A Directory Traversal issue allows a remote, unauthenticated attacker to enumerate file system information via the dir parameter to "listing.php" or "rss.php" API endpoints.
Recommendations For Modern Campus - Omni CMS version 2023.1, consider restricting access to the listing.php and rss.php API endpoints until a patch is available. As a temporary workaround, avoid using the dir parameter in these endpoints to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2023-35860

Affected Products

Modern Campus - Omni Cms